← WordPress Vulnerabilities
WordPress security by component

Create Block Theme

Create Block Theme (create-block) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 8.

Plugin slug: create-block

CVE-2026-16623: Create Block Theme pattern generation permits multisite PHP injection

Create Block Theme before 2.10.0 writes user-supplied pattern text into a generated PHP file without correctly escaping it. On WordPress multisite, a subsite Administrator holds the capability that gates pattern generation but lacks the capability that normally permits PHP file editing, allowing that user to inject PHP into the generated pattern and execute code on the server. The public advisory does not disclose the request route, action, parameter, generation function or output path.

PublishedAug 04, 2026
Known safe version2.10.0
Published vulnerabilities for create-block
Safe version
Aug 04, 2026 CVE-2026-16623
Create Block Theme pattern generation permits multisite PHP injection
Create Block Theme before 2.10.0 writes user-supplied pattern text into a generated PHP file without correctly escaping it. On WordPress multisite, a subsite Administrator holds the capability that gates pattern generation but lacks the capability that normally permits PHP file editing, allowing that user to inject PHP into the generated pattern and execute code on the server. The public advisory does not disclose the request route, action, parameter, generation function or output path.
2.10.0
CVE8.0
NVDPending