Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2026-16623

CVE-2026-16623

None
Open
TLP:CLEAR

Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite)

AI Analysis

No AI analysis yet.

Description

The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite subsite administrator (who holds the capability gating this action but is denied the capability that normally gates PHP file editing) to inject and execute arbitrary PHP code on the server.

Details

EPSS Score
0.24%

14.8th percentile

Confidence
90%
Published
Aug 4, 2026
Last Modified
Aug 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.