PT-2026-64229 · WordPress · Nexter Blocks

·

CVE-2026-15420

·

Published

2026-07-24

·

Updated

2026-07-24

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder versions prior to 5.0.1
Description The plugin is susceptible to Directory Traversal, a flaw that allows an attacker to access files and directories outside the intended folder. Authenticated users with subscriber-level access or higher can exploit this through the plus name parameter to delete arbitrary JS and CSS files on the server. This action can result in a denial of service or the destruction of essential plugin and theme assets.
Recommendations Update the plugin to a version newer than 5.0.0. Avoid using the plus name parameter until the update is applied.

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15420

Affected Products

Nexter Blocks