plugin

Create Block Theme Vulnerabilities

5 known security issues reported for the Create Block Theme WordPress plugin. Most recent disclosed Jul 24, 2026.

1 critical 1 high

Running Create Block Theme on your site? Check whether your installed version is affected.

Scan your site free

Create Block <= 2.9.0 - Code Injection to Authenticated (Admin+) PHP Code Injection

high

The Create Block plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.9.0. This is due to use of `edit_theme_options` instead of `edit_themes` in the REST route permission callbacks, allowing sub-site administrators on multisite installations (who hold `edit_theme_options` but not `e...

CVSS:
8.8
Affected:
up to 2.9.0
Fixed in:
2.10.0
Disclosed:
Jul 24, 2026

CVE-2026-16623 on NVD →

Create Block Theme <= 1.2.1 - Unauthenticated Arbitrary File Upload

critical

The Create Block Theme plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization via the save_local_fonts_to_theme function among others in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server wh...

CVSS:
9.8
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Oct 5, 2022

Create Block Theme [create-block-theme] < 1.2.2

unknown

Unauthenticated Arbitrary File Upload vulnerability discovered in WordPress Create Block Theme plugin (versions <= 1.2.1). Update the WordPress Create Block Theme plugin to the latest available version (at least 1.2.2).

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Oct 5, 2022

Create Block Theme [create-block-theme] < 1.2.2

unknown

The Create Block Theme plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization via the save_local_fonts_to_theme function among others in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server wh...

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Oct 5, 2022

Create Block Theme [create-block-theme] < 1.2.2

unknown

The plugin does not have authorisation and CSRF checks, as well as does not validate the file to be uploaded, which could allow unauthenticated attackers to upload arbitrary files to the server

Affected:
up to 1.2.2
Fixed in:
1.2.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database