The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary JS/CSS files on the server, which can lead to denial of service or destruction of critical plugin and theme assets.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 24 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jul 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Posimyththemes
Posimyththemes nexter Blocks – Gutenberg Blocks, Page Builder & Ai Website Builder Wordpress Wordpress wordpress |
|
| Vendors & Products |
Posimyththemes
Posimyththemes nexter Blocks – Gutenberg Blocks, Page Builder & Ai Website Builder Wordpress Wordpress wordpress |
Fri, 24 Jul 2026 03:45:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-07-24T22:10:12.300Z
Reserved: 2026-07-10T15:00:42.141Z
Link: CVE-2026-15420
Updated: 2026-07-24T22:10:08.096Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-27T06:45:03Z
Weaknesses