← العودة للجدول
CVE-2026-8365
CVE-2026-8365 — The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to
📅 2026-06-09
🟠 High 🔥 No NVD Exploit Web CVSS 8.8

📋 الوصف الكامل

The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration in versions up to and including 2.1.35. This is due to insufficient input sanitization in the blocksy_sanitize_post_meta_options() function, which only blocks values containing '' and does not prevent serial

💻 الأنظمة المتأثرة

WordPress | PHP

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-8365

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v2.1.35

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←