The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-345 | |
| Metrics |
cvssV3_1
|
Sun, 09 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-784 |
Sun, 09 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing. | |
| Title | Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-08-09T06:00:12.345Z
Updated: 2026-08-11T19:47:38.582Z
Reserved: 2026-07-24T10:10:03.572Z
Link: CVE-2026-17011
Updated: 2026-08-11T19:45:24.103Z
Status : Received
Published: 2026-08-09T06:18:10.180
Modified: 2026-08-11T20:17:34.623
Link: CVE-2026-17011
No data.