Vulnerabilities > Wpdeveloper > Essential Blocks PRO > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-10-20 CVE-2023-4402 Deserialization of Untrusted Data vulnerability in Wpdeveloper Essential Blocks and Essential Blocks PRO
The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function.
network
low complexity
wpdeveloper CWE-502
critical
9.8