GHSA-5rm6-jpq7-cq95HighCVSS 7.2
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for...
🔗 CVE IDs covered (1)
📋 Description
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the save_ai_generated_image() function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2026-10586
- https://plugins.trac.wordpress.org/browser/essential-blocks/tags/6.1.3/includes/Integrations/AI/AI.php#L171
- https://www.wordfence.com/threat-intel/vulnerabilities/id/08906577-162c-4875-b16c-18d4912c2611?source=cve
- https://github.com/advisories/GHSA-5rm6-jpq7-cq95