CVE-2023-4402: Essential Blocks <= 4.2.0 - Unauthenticated PHP Object Injection via products
The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the getproducts function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4402?
CVE-2023-4402 is a vulnerability in the Essential Blocks plugin for WordPress that allows unauthenticated attackers to inject a PHP Object.
What is the severity of CVE-2023-4402?
The severity of CVE-2023-4402 is critical with a CVSS score of 9.8.
How does CVE-2023-4402 impact the Essential Blocks plugin?
CVE-2023-4402 impacts the Essential Blocks plugin by allowing unauthenticated attackers to perform PHP Object Injection via deserialization of untrusted input.
Which versions of the Essential Blocks plugin are affected by CVE-2023-4402?
Versions of the Essential Blocks plugin up to and including 4.2.0 are affected by CVE-2023-4402.
Is there a patch available to fix CVE-2023-4402?
Yes, a patch is available to fix CVE-2023-4402. It is recommended to update to version 4.2.1 of the Essential Blocks plugin.