Impact
The vulnerability allows any WordPress user who can upload files, such as a user with Author role, to upload an SVG file that is not sanitized. When that SVG is accessed, the embedded malicious JavaScript executes in the victim’s browser, resulting in Stored Cross‑Site Scripting. This can lead to theft of user sessions, defacement of the site, or execution of arbitrary code within the context of the logged‑in user. The weakness is a classic input validation flaw and is identified as CWE‑79.
Affected Systems
The flaw exists in the Nexter Blocks WordPress plugin, affecting all installations of the plugin prior to version 5.0.2. No other vendors or products are listed. Since the plugin version information is limited, any instance using a pre‑5.0.2 release is vulnerable.
Risk and Exploitability
The vulnerability is exploitable without requiring elevated privileges beyond those needed to upload files, which in many sites is granted to Authors. Because the EPSS score is not available and the flaw is not listed in the CISA KEV catalog, the publicly known exploitation probability is uncertain, but the high damage potential of Stored XSS warrants immediate attention. No CVSS score is provided, but the flaw’s impact is severe if an attacker can influence an attacker’s victim audience.
OpenCVE Enrichment