PT-2026-69267 · WordPress · Nexter Blocks

·

CVE-2026-17011

·

Published

2026-08-09

·

Updated

2026-08-11

CVSS v3.1

3.8

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Nexter Blocks versions prior to 5.0.2
Description Insufficient access control in a REST endpoint allows users with the Contributor role or higher to save arbitrary global CSS. This stored CSS is rendered site-wide on the front end, which can lead to defacement, content hiding, and UI redressing (a technique used to trick a user into performing an action in a different application than the one they intended).
Recommendations Update Nexter Blocks to version 5.0.2 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17011

Affected Products

Nexter Blocks