Create Block <= 2.9.0 - Code Injection to Authenticated (Admin+) PHP Code Injection
high
The Create Block plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.9.0. This is due to use of `edit_theme_options` instead of `edit_themes` in the REST route permission callbacks, allowing sub-site administrators on multisite installations (who hold `edit_theme_options` but not `e...
- CVSS:
- 8.8
- Affected:
- up to 2.9.0
- Fixed in:
- 2.10.0
- Disclosed:
- Jul 24, 2026
CVE-2026-16623 on NVD →
Create Block Theme <= 1.2.1 - Unauthenticated Arbitrary File Upload
critical
The Create Block Theme plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization via the save_local_fonts_to_theme function among others in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server wh...
- CVSS:
- 9.8
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- Oct 5, 2022
Create Block Theme [create-block-theme] < 1.2.2
unknown
Unauthenticated Arbitrary File Upload vulnerability discovered in WordPress Create Block Theme plugin (versions <= 1.2.1).
Update the WordPress Create Block Theme plugin to the latest available version (at least 1.2.2).
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Oct 5, 2022
Create Block Theme [create-block-theme] < 1.2.2
unknown
The Create Block Theme plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization via the save_local_fonts_to_theme function among others in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server wh...
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Oct 5, 2022
Create Block Theme [create-block-theme] < 1.2.2
unknown
The plugin does not have authorisation and CSRF checks, as well as does not validate the file to be uploaded, which could allow unauthenticated attackers to upload arbitrary files to the server
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database