wpdevteam Vulnerabilities and Affected Products
Vulnerabilities associated with Essential Blocks Pro.
Products
Clear product- Essential Addons for Elementor – Popular Elementor Templates & Widgets49 vulnerabilities
- Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns22 vulnerabilities
- EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more17 vulnerabilities
- BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor5 vulnerabilities
- NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar5 vulnerabilities
- BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot2 vulnerabilities
- Essential Blocks Pro2 vulnerabilities
- EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more1 vulnerability
- SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher1 vulnerability
- Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud!1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-4386HIGH | Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via queriesThe Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_posts function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. CWE-502Oct 20, 2023 | CVSS8.1v3.1 | EPSS0.768% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4402HIGH | Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via productsThe Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. CWE-502Oct 20, 2023 | CVSS8.1v3.1 | EPSS1.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |