AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-17011

LOW · CVSS 3.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-08-09 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Nexter Blocks WordPress plugin prior to version 5.0.2 is vulnerable due to insufficient access controls on a REST endpoint, allowing users with Contributor roles to save arbitrary global CSS. This can lead to site defacement, content manipulation, and UI redressing, posing a significant risk to the integrity and appearance of affected websites. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-17011
Severity
LOW
CVSS
3.8
EPSS
0.12%
WordPress

Original NVD Description

The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.