PT-2026-68384 · WordPress · Nexter Blocks
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nexter Blocks versions prior to 5.0.2
Description
Stored Cross-Site Scripting occurs because the plugin fails to sanitize uploaded SVG files. Users with file upload permissions, such as the Author role by default, can upload an SVG file containing malicious JavaScript. This script executes when the file is accessed.
Recommendations
Update Nexter Blocks to version 5.0.2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nexter Blocks