The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary JS/CSS files on the server, which can lead to denial of service or destruction of critical plugin and theme assets.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 24 Jul 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Posimyththemes
Posimyththemes nexter Blocks – Gutenberg Blocks, Page Builder & Ai Website Builder Wordpress Wordpress wordpress |
|
| Vendors & Products |
Posimyththemes
Posimyththemes nexter Blocks – Gutenberg Blocks, Page Builder & Ai Website Builder Wordpress Wordpress wordpress |
Fri, 24 Jul 2026 03:45:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-07-24T02:31:59.549Z
Reserved: 2026-07-10T15:00:42.141Z
Link: CVE-2026-15420
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T04:30:03Z
Weaknesses