CVE Database /
CVE-2023-6623
CVE · Critical
CVE-2023-6623 — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.4.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-6623
|
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.4.3 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Critical
9.8
|
< 4.4.3
|
4.4.3 |
2023-12-21 |
—
|
CVE-2023-6623
The Essential Blocks plugin for WordPress contains a local file inclusion vulnerability in versions 4.4.2 and earlier, accessible through the /wp-json/essential-blocks/v1/queries REST API endpoint without requiring authentication. An unauthenticated attacker can exploit this flaw to include and execute arbitrary files from the server, potentially running malicious PHP code. This vulnerability could allow an attacker to circumvent security restrictions, access confidential information, or execute code by uploading and subsequently including files that appear harmless such as images.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings