PT-2026-69267 · WordPress · Nexter Blocks
CVSS v3.1
3.8
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Nexter Blocks versions prior to 5.0.2
Description
Insufficient access control in a REST endpoint allows users with the Contributor role or higher to save arbitrary global CSS. This stored CSS is rendered site-wide on the front end, which can lead to defacement, content hiding, and UI redressing (a technique used to trick a user into performing an action in a different application than the one they intended).
Recommendations
Update Nexter Blocks to version 5.0.2 or later.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nexter Blocks