Description
The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary JS/CSS files on the server, which can lead to denial of service or destruction of critical plugin and theme assets.
Published: 2026-07-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder is vulnerable to a directory traversal flaw triggered by the 'plus_name' parameter. The flaw allows authenticated users with subscriber-level access or above to craft requests that reference arbitrary file paths and delete JavaScript or CSS assets stored on the server. Removing these files can cause front‑end failures and may result in a denial‑of‑service attack by breaking the visual and interactive elements of the site.

Affected Systems

The affected product the Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress, provided by posimyththemes. All released versions up to and including 5.0.0 are impacted. No specific patch versions are listed, so any installation at or below 5.0.0 is considered vulnerable.

Risk and Exploitability

The CVSS score of 4.3 places the vulnerability in the low‑moderate severity range, and the EPSS score of less than 1% indicates a very low probability of exploitation at present. The attack vector is an authenticated request; an attacker needs only a subscriber account, which is commonly granted to content contributors. Because the flaw does not provide remote code execution, but rather the ability to delete key front‑end files, it may lead to a service interruption. The vulnerability is not listed in the CISA KEV catalog, suggesting that no publicly available exploit has been reported yet.

Generated by OpenCVE AI on August 3, 2026 at 20:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Nexter Blocks to the latest available version where this defect is fixed.
  • If an update is not yet available, consider disabling the plugin or removing the block type that accepts the 'plus_name' parameter to eliminate the attack surface.
  • Enforce strict file system permissions on the JavaScript and CSS directories so that only authorized users can modify these assets, and ensure directory traversal is mitigated through input validation or by using an allowlist for the 'plus_name' parameter.

Generated by OpenCVE AI on August 3, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Posimyththemes
Posimyththemes nexter Blocks – Gutenberg Blocks, Page Builder & Ai Website Builder
Wordpress
Wordpress wordpress
Vendors & Products Posimyththemes
Posimyththemes nexter Blocks – Gutenberg Blocks, Page Builder & Ai Website Builder
Wordpress
Wordpress wordpress

Fri, 24 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Description The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary JS/CSS files on the server, which can lead to denial of service or destruction of critical plugin and theme assets.
Title Nexter Blocks <= 5.0.0 - Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion via 'plus_name' Parameter
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Posimyththemes Nexter Blocks – Gutenberg Blocks, Page Builder & Ai Website Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-24T22:10:12.300Z

Reserved: 2026-07-10T15:00:42.141Z

Link: CVE-2026-15420

cve-icon Vulnrichment

Updated: 2026-07-24T22:10:08.096Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T04:16:51.857

Modified: 2026-07-24T23:16:49.840

Link: CVE-2026-15420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:45:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')