Impact
The Nexa Blocks plugin for WordPress contains a stored cross‑site scripting flaw within its Google Maps widget. User‑supplied attributes are not properly sanitized or escaped, allowing an authenticated contributor or higher to insert arbitrary JavaScript. Once injected, the script executes in the browser of anyone who views the affected page, potentially exfiltrating data or hijacking sessions. This vulnerability is classified as CWE‑79.
Affected Systems
The affected systems are WordPress sites that use the Nexa Blocks plugin, version 1.1.0 or earlier. The plugin, developed by wpdive, provides Gutenberg blocks and a page builder for the Gutenberg editor and Full‑Site Editing. No specific sub‑versions are listed beyond the statement that all releases up to and including 1.1.0 are vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, while an EPSS score of <1% suggests a low probability of public exploitation at this time. The vulnerability is not yet listed in CISA’s Known Exploited Vulnerabilities catalog. Attackers must possess contributor‑level credentials or higher, after which they can embed malicious scripts that impact all visitors to the affected page. The risk is primarily confined to authenticated attackers with sufficient role permissions, but the impact is broad, affecting every user who views the compromised content.
OpenCVE Enrichment
EUVD