Impact
The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin stored a cross‑site scripting flaw in the commentIcon block attribute. Because the input is not properly sanitized and the output is not escaped, an authenticated user with contributor‑level or higher privileges can insert malicious JavaScript. When a page containing the injected value is viewed, the script runs in the victim’s browser, compromising client‑side confidentiality and integrity. This issue is a classic stored XSS identified as CWE‑79.
Affected Systems
All WordPress sites running the Nexter Blocks plugin by posimyththemes, versions 4.7.4 and older, are affected. The vulnerability is present in all versions up to 4.7.4; versions newer than 4.7.4 may not contain the flaw, but the current data does not confirm whether they address it.
Risk and Exploitability
The CVSS base score is 6.4, which places the vulnerability in the moderate severity range. The EPSS score of < 1% indicates a very low but non‑zero chance of active exploitation in the wild, and the plugin is not listed in CISA KEV. The attack vector requires an authenticated contributor‑level account, a common role in WordPress, meaning an insider or compromised account could easily execute the exploit.
OpenCVE Enrichment