Description
The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary JS/CSS files on the server, which can lead to denial of service or destruction of critical plugin and theme assets.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 24 Jul 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Posimyththemes
Posimyththemes nexter Blocks – Gutenberg Blocks, Page Builder & Ai Website Builder Wordpress Wordpress wordpress |
|
| Vendors & Products |
Posimyththemes
Posimyththemes nexter Blocks – Gutenberg Blocks, Page Builder & Ai Website Builder Wordpress Wordpress wordpress |
Fri, 24 Jul 2026 03:45:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-07-24T02:31:59.549Z
Reserved: 2026-07-10T15:00:42.141Z
Link: CVE-2026-15420
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T04:30:03Z
Weaknesses
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')