Impact
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder is vulnerable to a directory traversal flaw triggered by the 'plus_name' parameter. The flaw allows authenticated users with subscriber-level access or above to craft requests that reference arbitrary file paths and delete JavaScript or CSS assets stored on the server. Removing these files can cause front‑end failures and may result in a denial‑of‑service attack by breaking the visual and interactive elements of the site.
Affected Systems
The affected product the Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress, provided by posimyththemes. All released versions up to and including 5.0.0 are impacted. No specific patch versions are listed, so any installation at or below 5.0.0 is considered vulnerable.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in the low‑moderate severity range, and the EPSS score of less than 1% indicates a very low probability of exploitation at present. The attack vector is an authenticated request; an attacker needs only a subscriber account, which is commonly granted to content contributors. Because the flaw does not provide remote code execution, but rather the ability to delete key front‑end files, it may lead to a service interruption. The vulnerability is not listed in the CISA KEV catalog, suggesting that no publicly available exploit has been reported yet.
OpenCVE Enrichment