Description
Missing Authorization vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nexter Blocks: from n/a through <= 4.5.4.
Published: 2025-08-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Missing Authorization flaw in the POSIMYTH Nexter Blocks plugin, also known as the-plus-addons-for-block-editor. It stems from incorrectly configured access control security levels. When triggered, it allows a user to access or modify data and privileged functions that they should not be able to reach. The weakness is classified as CWE‑862.

Affected Systems

The affected product is the POSIMYTH Nexter Blocks plugin, named the-plus-addons-for-block-editor. All releases from the earliest version through version 4.5.4 are vulnerable, so any WordPress site running the plugin at these or older versions is at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity overall. The EPSS score is below 1 %, suggesting that the likelihood of public exploitation is very low at present. The vulnerability is not included in CISA’s KEV catalog. Based on the description, it is inferred that an attacker would need to have some level of authenticated WordPress access, such as an editor or administrator role, but the missing authorization check allows them to perform actions beyond their intended permissions. Mitigation is straightforward by applying a patch or removing the plugin from the site.

Generated by OpenCVE AI on April 30, 2026 at 08:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Nexter Blocks plugin to a version newer than 4.5.4 from the vendor’s official website.
  • If an upgrade cannot be applied immediately, disable the plugin or remove it entirely for users who do not require block editor capabilities.
  • Check the vendor’s website regularly for new security updates and apply any patches as soon as they become available.

Generated by OpenCVE AI on April 30, 2026 at 08:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24916 Missing Authorization vulnerability in POSIMYTH Nexter Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Nexter Blocks: from n/a through 4.5.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in POSIMYTH Nexter Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Nexter Blocks: from n/a through 4.5.4. Missing Authorization vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nexter Blocks: from n/a through <= 4.5.4.
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Fri, 15 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Posimyth
Posimyth nexter Blocks
Wordpress
Wordpress wordpress
Vendors & Products Posimyth
Posimyth nexter Blocks
Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 18:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in POSIMYTH Nexter Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Nexter Blocks: from n/a through 4.5.4.
Title WordPress Nexter Blocks Plugin <= 4.5.4 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Posimyth Nexter Blocks
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:36.760Z

Reserved: 2025-07-28T10:56:41.543Z

Link: CVE-2025-54739

cve-icon Vulnrichment

Updated: 2025-08-14T19:53:33.175Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T19:15:41.730

Modified: 2026-04-23T15:32:54.993

Link: CVE-2025-54739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T09:00:20Z

Weaknesses