Nexter Blocks <= 5.0.1 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 5.0.1
- Fixed in:
- 5.0.2
- Disclosed:
- Aug 3, 2026
CVE-2025-15678 on NVD →
Nexter Blocks <= 5.0.1 - Payment Bypass to Authenticated (Contributor+) Stored CSS Injection
medium
The Nexter Blocks plugin for WordPress is vulnerable to Payment Bypass in versions up to, and including, 5.0.1. This is due to a lack of server-side payment verification. This makes it possible for authenticated attackers, with contributor-level access and above, to bypass payments.
- CVSS:
- 4.3
- Affected:
- up to 5.0.1
- Fixed in:
- 5.0.2
- Disclosed:
- Aug 3, 2026
CVE-2026-17011 on NVD →
Nexter Blocks <= 5.0.0 - Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion via 'plus_name' Parameter
medium
The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary JS/...
- CVSS:
- 4.3
- Affected:
- up to 5.0.0
- Fixed in:
- 5.0.1
- Disclosed:
- Jul 23, 2026
CVE-2026-15420 on NVD →
Nexter Blocks <= 4.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'commentIcon' Block Attribute
medium
The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...
- CVSS:
- 6.4
- Affected:
- up to 4.7.4
- Fixed in:
- 4.7.5
- Disclosed:
- Jul 7, 2026
CVE-2026-6740 on NVD →
Nexter Blocks <= 4.7.0 - Unauthenticated Information Exposure
medium
The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 4.7.0
- Fixed in:
- 4.7.1
- Disclosed:
- Mar 26, 2026
CVE-2026-39516 on NVD →
Nexter Blocks <= 4.6.3 - Authenticated (Subscriber+) Information Exposure
medium
The Nexter Gutenberg Blocks – Website Builder & 1000+ Starter Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.6.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration...
- CVSS:
- 4.3
- Affected:
- up to 4.6.3
- Fixed in:
- 4.6.4
- Disclosed:
- Jan 26, 2026
CVE-2026-24377 on NVD →
Nexter Blocks <= 4.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access a...
- CVSS:
- 6.4
- Affected:
- up to 4.5.4
- Fixed in:
- 4.5.5
- Disclosed:
- Aug 18, 2025
CVE-2025-8567 on NVD →
Nexter Blocks <= 4.5.4 - Missing Authorization
medium
The Nexter Blocks – WordPress Gutenberg Blocks & 1000+ Starter Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.5.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.5.4
- Fixed in:
- 4.5.5
- Disclosed:
- Aug 14, 2025
CVE-2025-54739 on NVD →
Nexter Blocks <= 4.0.7 - Missing Authorization
medium
The Nexter Blocks – WordPress Gutenberg Blocks & 1000+ Starter Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to...
- CVSS:
- 4.3
- Affected:
- up to 4.0.7
- Fixed in:
- 4.0.8
- Disclosed:
- Jan 3, 2025
CVE-2024-56294 on NVD →
Nexter Blocks <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...
- CVSS:
- 6.4
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.5
- Disclosed:
- Dec 30, 2024
CVE-2024-56246 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 4.3.1
- Fixed in:
- 4.3.2
- Disclosed:
- Dec 3, 2024
CVE-2024-5020 on NVD →
Nexter Blocks <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...
- CVSS:
- 6.4
- Affected:
- up to 3.3.3
- Fixed in:
- 4.0.0
- Disclosed:
- Oct 24, 2024
CVE-2024-50452 on NVD →
The Plus Blocks for Block Editor | Gutenberg <= 3.2.5 - Missing Authorization
medium
The The Plus Blocks for Block Editor | Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the Tp_f_delete_transient() function in versions up to, and including, 3.2.5. This makes it possible for authenticated attackers, with subscriber-level access and above,...
- CVSS:
- 4.3
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.6
- Disclosed:
- Apr 25, 2024
CVE-2024-33572 on NVD →
The Plus Blocks for Block Editor | Gutenberg <= 3.2.5 - Reflected Cross-Site Scripting
medium
The The Plus Blocks for Block Editor | Gutenberg plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 6.1
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.6
- Disclosed:
- Mar 28, 2024
CVE-2024-30435 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database