Record summary

CVE-2023-6623 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 13, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 13, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Essential Blocks

Default status: unaffected

CVE ListBefore 4.4.3affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALEssential Blocks < 4.4.3 - Local File InclusionCVSS 9.8

Wordpress Essential Blocks plugin prior to 4.4.3 was discovered to be vulnerable to a significant Local File Inclusion vulnerability that may be exploited by any attacker, regardless of whether they have an account on the site.

Impact

An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.

Remediation

Upgrade to the latest version of Essential Blocks 4.4.3 to fix this issue.

WeaknessesCWE-22
Authorsiamnoooob, rootxharsh, pdresearch, coldfish
Template tagswpscancvecve2023wpwp-pluginwordpressessential-blockslfiwpdevelopervkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:wpdeveloper:essential_blocks:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/essential-blocks/
FOFA: body=/wp-content/plugins/essential-blocks/

Source: ProjectDiscovery

References

3