Medium severity4.3NVD Advisory· Published Jun 9, 2023· Updated Apr 8, 2026
CVE-2023-2086
CVE-2023-2086
Description
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is present, it is only executed when a nonce is provided. Not providing a nonce results in the nonce verification to be skipped. There is no capability check.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:wpdeveloper:essential_blocks:*:*:*:*:*:wordpress:*:*Range: <=4.0.6
- Range: <=4.0.6
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.