plugin

Nexter Extension Vulnerabilities

7 known security issues reported for the Nexter Extension WordPress plugin. Most recent disclosed Jan 20, 2026.

2 high 2 medium

Running Nexter Extension on your site? Check whether your installed version is affected.

Scan your site free

Nexter Extension – Site Enhancements Toolkit <= 4.4.6 - Unauthenticated PHP Object Injection via 'nxt_unserialize_replace'

high

The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.6 via deserialization of untrusted input in the 'nxt_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known...

CVSS:
8.1
Affected:
up to 4.4.6
Fixed in:
4.4.7
Disclosed:
Jan 20, 2026

CVE-2026-0726 on NVD →

Nexter Extension &#8211; Site Enhancements Toolkit [nexter-extension] < 4.4.2

unknown

[en] The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nxt-year' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with C...

Affected:
up to 4.4.2
Fixed in:
4.4.2
Disclosed:
Dec 2, 2025

CVE-2025-13731 on NVD →

Nexter Extension <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nxt-year' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contri...

CVSS:
6.4
Affected:
up to 4.4.1
Fixed in:
4.4.2
Disclosed:
Dec 1, 2025

CVE-2025-13731 on NVD →

Nexter Extension &#8211; Site Enhancements Toolkit [nexter-extension] < 2.0.4

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in POSIMYTH Nexter Extension.This issue affects Nexter Extension: from n/a through 2.0.3.

Affected:
up to 2.0.4
Fixed in:
2.0.4
Disclosed:
Dec 29, 2023

CVE-2023-45751 on NVD →

Nexter Extension &#8211; Site Enhancements Toolkit [nexter-extension] < 2.0.4

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in POSIMYTH Nexter Extension plugin <= 2.0.3 versions.

Affected:
up to 2.0.4
Fixed in:
2.0.4
Disclosed:
Oct 24, 2023

CVE-2023-45750 on NVD →

Nexter Extension <= 2.0.3 - Authenticated(Editor+) Remote Code Execution via metabox

high

The Nexter Extension plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.3 via the nxt-code-php-snippet metabox. This allows authenticated attackers with editor-level privileges and above to execute code on the server.

CVSS:
7.2
Affected:
up to 2.0.3
Fixed in:
2.0.4
Disclosed:
Oct 12, 2023

CVE-2023-45751 on NVD →

Nexter Extension <= 2.0.3 - Reflected Cross-Site Scripting via post and post_id

medium

The Nexter Extension plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post’ and 'post_id' parameters in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

CVSS:
6.1
Affected:
up to 2.0.3
Fixed in:
2.0.4
Disclosed:
Oct 12, 2023

CVE-2023-45750 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database