Impact
The Create Block Theme WordPress plugin before version 2.10.0 writes user‑supplied text into a generated PHP pattern file without proper escaping. A multisite subsite administrator, who normally lacks the capability that gates PHP file editing, can trigger this action from the admin interface and inject arbitrary PHP code that will be executed by the server. This flaw enables an attacker who can become a subsite administrator to run arbitrary code on the entire WordPress site, compromising data, installing malware, or taking control of the environment. The weakness is a classic code injection problem (CWE‑94).
Affected Systems
Any WordPress site running the Create Block Theme plugin with a version older than 2.10.0 on a multisite network is affected. Only the multisite subsite administrators who can trigger the pattern‑save operation are required to exploit the flaw; other roles do not need additional privileges.
Risk and Exploitability
Because the flaw results in uncontrolled PHP code execution, the potential impact is high. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the attack vector is local via an authorized but privileged attacker. A multisite subsite administrator can exploit this flaw without needing to compromise higher‑level administrative accounts. The lack of an official remedy means the risk is immediate and significant, especially for sites that rely on the plugin for core functionality.
OpenCVE Enrichment