CyberRota Analysis
AI-GeneratedThe Nexter Blocks WordPress plugin prior to version 5.0.2 is vulnerable due to insufficient access controls on a REST endpoint, allowing users with Contributor roles to save arbitrary global CSS. This can lead to site defacement, content manipulation, and UI redressing, posing a significant risk to the integrity and appearance of affected websites. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.