CVE-2023-6623: Essential Blocks < 4.4.3 - Unauthenticated Local File Inclusion
Published Jan 15, 2024
·Updated
The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.
Affected Software
1 affected component
WPDeveloper Essential Blocks Wordpress<4.4.3
Event History
Jan 15, 2024
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-6623?
CVE-2023-6623 has a high severity level due to the risk of Local File Inclusion attacks.
2
How do I fix CVE-2023-6623?
To fix CVE-2023-6623, update the Essential Blocks WordPress plugin to version 4.4.3 or later.
3
What software is affected by CVE-2023-6623?
CVE-2023-6623 affects the Essential Blocks WordPress plugin versions prior to 4.4.3.
4
What types of attacks can CVE-2023-6623 lead to?
CVE-2023-6623 can lead to Local File Inclusion attacks when exploited by unauthenticated attackers.
5
Is authentication required to exploit CVE-2023-6623?
No, CVE-2023-6623 can be exploited by unauthenticated attackers, allowing them to overwrite local variables.