WordPress security by component
Create Block Theme
Create Block Theme (create-block) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 8.
Plugin slug:
create-blockLatest vulnerability
CVE-2026-16623: Create Block Theme pattern generation permits multisite PHP injection
Create Block Theme before 2.10.0 writes user-supplied pattern text into a generated PHP file without correctly escaping it. On WordPress multisite, a subsite Administrator holds the capability that gates pattern generation but lacks the capability that normally permits PHP file editing, allowing that user to inject PHP into the generated pattern and execute code on the server. The public advisory does not disclose the request route, action, parameter, generation function or output path.
| Safe version |
|
||
|---|---|---|---|
| Aug 04, 2026 |
CVE-2026-16623
Create Block Theme pattern generation permits multisite PHP injection
Create Block Theme before 2.10.0 writes user-supplied pattern text into a generated PHP file without correctly escaping it. On WordPress multisite, a subsite Administrator holds the capability that gates pattern generation but lacks the capability that normally permits PHP file editing, allowing that user to inject PHP into the generated pattern and execute code on the server. The public advisory does not disclose the request route, action, parameter, generation function or output path.
|
2.10.0 |
CVE8.0
NVDPending
|