Skip to main content

CVE-2023-4402

8.1
HIGHCVSS v3.1 Base Score
2.87%
LOW RiskEPSS (87th percentile)

The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Published: 10/20/2023
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

2.87%LOW Exploitation Risk
87th percentile

This vulnerability has a 2.87% probability of being exploited in the next 30 days, ranking higher than 87% of all scored CVEs.

Related Vulnerabilities