High CVSS: HIGH CVE-2023-4402 vulnerability

CVE-2023-4402: The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection

Tracked since May 6, 2026 View on NVD

CVSS Breakdown

8.1
CVSS Base Score
HIGH
Attack Vector
N/A
Requires physical access to exploit.
CIA Impact
Confidentiality N/A
Integrity N/A
Availability N/A

Insurance Impact Assessment

🛡️
Significant Impact

High-severity vulnerabilities may affect cyber insurance pricing and coverage terms. Demonstrating patch management reduces underwriting friction.

CVE CVE-2023-4402 with CVSS 8.1. The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.

View on NVD

Assess your exposure

Is your organization vulnerable? Run a free domain exposure scan to check.

← Back to Threat Feed