What is CVE-2026-16623?
The Create Block WordPress plugin before version 2.10.0 fails to properly escape user-supplied text when writing it into a generated PHP pattern file. This vulnerability allows a multisite subsite administrator, who lacks the capability to edit PHP files, to potentially achieve remote code execution. Users should immediately update the plugin to version 2.10.0 or later.
Azərbaycanca: Create Block WordPress plaginində 2.10.0 versiyasından əvvəl istifadəçi tərəfindən daxil edilən mətn düzgün escapə olunmur və nəticədə yaradılan PHP faylına yazılır. Bu zəiflik multisite şəbəkəsində subsite administratoruna PHP fayllarını redaktə etmək icazəsi olmasa belə, uzaqdan kod icrası (remote code execution) həyata keçirməyə imkan verir. Plagini dərhal 2.10.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
In which version of the Create Block WordPress plugin is the CVE-2026-16623 vulnerability fixed?
This vulnerability is fixed in version 2.10.0.
Who is allowed to achieve remote code execution (RCE) without the capability to edit PHP files in the CVE-2026-16623 vulnerability?
A multisite subsite administrator.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.