Extension WordPress
Vulnérabilités Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
Cette page rassemble les failles publiées pour Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
5 fiches
Nexa Blocks <= 1.1.1 – Unauthenticated Blind Server-Side Request Forgery via 'demo_json_file' Parameter
The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due to the import_demo() function accepting…
*-1.1.1
Non indiqué
19/05/2026
Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 1.1.1 – Unauthenticated PHP Object Injection
The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1.1 via deserialization of untrusted input. This makes it possible…
*-1.1.1
Non indiqué
18/03/2026
Nexa Blocks <= 1.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps Widget
The Nexa Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Google Maps widget in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-1.1.0
1.1.1
29/09/2025
Nexa Blocks <= 1.1.0 – Authenticated (Contributor+) Server-Side Request Forgery
The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.0. This makes it possible for authenticated attackers, with…
*-1.1.0
Non indiqué
05/06/2025
Nexa Blocks <= 1.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Nexa Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-1.1.0
Non indiqué
05/06/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.