CVE-2026-16623: CWE-94 Improper Control of Generation of Code ('Code Injection') in Create Block Theme
The Create Block WordPress plugin before version 2.10.0 contains a code injection vulnerability. This flaw allows a multisite subsite administrator, who normally lacks PHP file editing permissions but has the capability to perform the vulnerable action, to inject and execute arbitrary PHP code on the server. This occurs because user-supplied text is not properly escaped before being written into a generated PHP pattern file.
AI Analysis
Technical Summary
CVE-2026-16623 is a code injection vulnerability (CWE-94) in the Create Block WordPress plugin prior to version 2.10.0. The vulnerability arises from improper escaping of user input before writing it into a PHP pattern file. A multisite subsite administrator with specific capabilities can exploit this to execute arbitrary PHP code on the server, bypassing normal capability restrictions on PHP file editing.
Potential Impact
Successful exploitation allows a multisite subsite administrator to execute arbitrary PHP code on the server, potentially leading to full server compromise or unauthorized actions beyond their intended permissions. This elevates the privileges of the subsite administrator in the multisite WordPress environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict multisite subsite administrator capabilities to trusted users only and monitor for suspicious activity related to PHP file generation. Avoid granting unnecessary permissions that could enable exploitation.
CVE-2026-16623: CWE-94 Improper Control of Generation of Code ('Code Injection') in Create Block Theme
Description
The Create Block WordPress plugin before version 2.10.0 contains a code injection vulnerability. This flaw allows a multisite subsite administrator, who normally lacks PHP file editing permissions but has the capability to perform the vulnerable action, to inject and execute arbitrary PHP code on the server. This occurs because user-supplied text is not properly escaped before being written into a generated PHP pattern file.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-16623 is a code injection vulnerability (CWE-94) in the Create Block WordPress plugin prior to version 2.10.0. The vulnerability arises from improper escaping of user input before writing it into a PHP pattern file. A multisite subsite administrator with specific capabilities can exploit this to execute arbitrary PHP code on the server, bypassing normal capability restrictions on PHP file editing.
Potential Impact
Successful exploitation allows a multisite subsite administrator to execute arbitrary PHP code on the server, potentially leading to full server compromise or unauthorized actions beyond their intended permissions. This elevates the privileges of the subsite administrator in the multisite WordPress environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict multisite subsite administrator capabilities to trusted users only and monitor for suspicious activity related to PHP file generation. Avoid granting unnecessary permissions that could enable exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-22T14:59:28.691Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7187d1bf32cb7a34e19b53
Added to database: 08/04/2026, 06:33:53 UTC
Last enriched: 08/04/2026, 06:52:49 UTC
Last updated: 08/04/2026, 07:58:03 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.