CVE · High

CVE-2023-2288 — Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.2.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-2288 Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 2.2.6 Deserialization of Untrusted Data High 8.8 < 2.2.6 2.2.6 2023-05-02

CVE-2023-2288

The Otter - Gutenberg Blocks plugin through version 1.2.7 contains a deserialization vulnerability in the 'fallback' parameter that allows authenticated authors to exploit PHP object deserialization through PHAR wrappers, potentially executing arbitrary code if a POP chain exists and a malicious serialized file is successfully uploaded. This flaw requires the attacker to have author-level access and the ability to upload files containing the exploit payload. Versions 2.2.6 and later address this security issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.