CVE-2023-6623
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2023-6623 is a vulnerability affecting the Essential Blocks WordPress plugin before version 4.4.3. This issue allows unauthenticated attackers to manipulate local variables during template rendering over the REST API. The consequence of this vulnerability is the potential for Local File Inclusion attacks, which could result in unauthorized access or data exposure. Attackers can exploit this flaw to include and execute malicious code, posing a significant security risk. WordPress users are advised to update the plugin to the latest version to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.