The Nexter Blocks WordPress plugin before 5.0.2 does not...
Low severity
Unreviewed
Published
Aug 9, 2026
to the GitHub Advisory Database
•
Updated Aug 11, 2026
Description
Published by the National Vulnerability Database
Aug 9, 2026
Published to the GitHub Advisory Database
Aug 9, 2026
Last updated
Aug 11, 2026
The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.
References