← Back to browse · API

CVE-2023-6623

Severity
CRITICAL
CVSS
9.8
EPSS
0.50673
Risk score
56.94
CISA KEV
No
PoC
No
Published
2024-01-15
Modified
2025-06-11
First seen
2026-08-07
Aliases
EUVD-2023-58846, GHSA-PHJG-GJ5X-8J96
Products
Unknown:Essential Blocks 0 <4.4.3
Sources
euvd EUVD-2023-58846

Description

The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.

References