Back

HIGH

Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite)

Published Aug 4, 2026

Description

The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite subsite administrator (who holds the capability gating this action but is denied the capability that normally gates PHP file editing) to inject and execute arbitrary PHP code on the server.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Aug 4, 2026
Updated Aug 4, 2026
Reserved Jul 22, 2026
CISA Vulnrichment
Updated Aug 4, 2026
NVD
Status Deferred
Modified Aug 26, 2026
Red Hat
Severity n/a
Public date n/a