The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.
Metrics
Affected Vendors & Products
References
History
Sun, 09 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-784 |
Sun, 09 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing. | |
| Title | Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-09T06:00:12.345Z
Reserved: 2026-07-24T10:10:03.572Z
Link: CVE-2026-17011
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-09T07:30:04Z