Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection
Summary
| CVE | CVE-2026-17011 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-09 06:18:10 UTC |
| Updated | 2026-08-09 06:18:10 UTC |
| Description | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing. |
Risk And Classification
EPSS: 0.000970000 probability, percentile 0.008440000 (date 2026-08-09)
Problem Types: CWE-345 Insufficient Verification of Data Authenticity
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | Nexter Blocks | affected 5.0.2 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/a702e5cb-0fb3-419e-81df-fa5b26c81402 | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Vaibhav Narkhede (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.