CVE-2023-6623
Essential Blocks < 4.4.3 - Unauthenticated Local File Inclusion
Record summary
CVE-2023-6623 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 13, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 13, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Essential BlocksDefault status: unaffected | CVE List | Before 4.4.3 | affected |
essential_blocksBrowse wpdeveloper / essential_blocks | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALEssential Blocks < 4.4.3 - Local File InclusionCVSS 9.8
Wordpress Essential Blocks plugin prior to 4.4.3 was discovered to be vulnerable to a significant Local File Inclusion vulnerability that may be exploited by any attacker, regardless of whether they have an account on the site.
Impact
An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.
Remediation
Upgrade to the latest version of Essential Blocks 4.4.3 to fix this issue.
Source: ProjectDiscovery