CVE-2026-16623

CVE-2026-16623: Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite)

Vendor Unknown
Product Create Block Theme
Published August 4, 2026
Last update August 4, 2026

CVSS base score

What the vulnerability does

01Description

The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite subsite administrator (who holds the capability gating this action but is denied the capability that normally gates PHP file editing) to inject and execute arbitrary PHP code on the server.

Key dates

02Disclosure timeline

August 4, 2026 CVE published
August 4, 2026 Record updated