WordPress Plugin Vulnerabilities

Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection

Description

The plugin does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.

Proof of Concept

Affects Plugins

References

Classification

Type
CONTENT INJECTION
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Vaibhav Narkhede
Submitter
Vaibhav Narkhede
Verified
Yes

Timeline

Publicly Published
2026-08-03 (about 27 days ago)
Added
2026-08-03 (about 26 days ago)
Last Updated
2026-08-03 (about 26 days ago)

Other