The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.
History

Wed, 13 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-15T15:10:40.328Z

Updated: 2024-11-13T21:43:40.646Z

Reserved: 2023-12-08T14:24:56.244Z

Link: CVE-2023-6623

cve-icon Vulnrichment

Updated: 2024-08-02T08:35:14.900Z

cve-icon NVD

Status : Modified

Published: 2024-01-15T16:15:12.573

Modified: 2024-11-21T08:44:13.497

Link: CVE-2023-6623

cve-icon Redhat

No data.