Impact
The Nexter Blocks WordPress plugin version prior to 5.0.2 fails to enforce permission checks on a REST endpoint that saves global CSS, allowing users with Contributor privileges to inject arbitrary CSS that is rendered site‑wide. This client‑side injection can deface the site, conceal content, or manipulate the user interface, effectively giving attackers control over the visual presentation of the site. The weakness is a stored CSS injection flaw (CWE‑784).
Affected Systems
All WordPress sites running Nexter Blocks before version 5.0.2 are affected when a user has Contributor or higher privileges. The vulnerability applies to any environment where the plugin’s REST API is exposed and the Contributor role can be assigned, regardless of the specific WordPress theme or other plugins.
Risk and Exploitability
The CVSS score is not disclosed in the available data, and the EPSS score is listed as unavailable; the issue is not present in CISA’s KEV catalog. The likely attack vector requires an attacker to possess or compromise a Contributor account on the affected site, after which they can send a crafted request to the vulnerable endpoint to store malicious CSS. Attackers who gain such access can permanently modify the site’s appearance and potentially hide or alter content. Because the flaw is client‑side, remote code execution is not possible, but the impact on user experience and the potential for defacement make this a serious concern for sites that allow Contributor permissions.
OpenCVE Enrichment