CVE-2026-16623 - Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite)
CVE ID :CVE-2026-16623
Published : Aug. 4, 2026, 7:16 a.m. | 3 hours, 37 minutes ago
Description :The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite subsite administrator (who holds the capability gating this action but is denied the capability that normally gates PHP file editing) to inject and execute arbitrary PHP code on the server.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 4, 2026, 7:16 a.m. | 3 hours, 37 minutes ago
Description :The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite subsite administrator (who holds the capability gating this action but is denied the capability that normally gates PHP file editing) to inject and execute arbitrary PHP code on the server.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...