CVE-2026-17011
N/A
N/A
Summary
The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Nexter Blocks | 0 < 5.0.2 | affected |
Weaknesses
- CWE-345 Insufficient Verification of Data Authenticity
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.