Extension WordPress

Vulnérabilités Nexter Extension – Security, Performance, Code Snippets & Site Toolkit

Cette page rassemble les failles publiées pour Nexter Extension – Security, Performance, Code Snippets & Site Toolkit, leurs plages de versions affectées et les correctifs signalés dans la base locale.

4Vulnérabilités
0Critiques
4Avec correctif
8,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Nexter Extension – Security, Performance, Code Snippets & Site Toolkit

4 fiches

CVE-2026-0726 Élevée · 8,1
Nexter Extension – Security, Performance, Code Snippets & Site Toolkit

Nexter Extension – Site Enhancements Toolkit <= 4.4.6 – Unauthenticated PHP Object Injection via 'nxt_unserialize_replace'

The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.6 via deserialization of untrusted input in the 'nxt_unserialize_replace' function. This makes it possible for…

Versions affectées

*-4.4.6

Correctif

4.4.7

Publication

20/01/2026

CVE-2025-13731 Moyenne · 6,4
Nexter Extension – Security, Performance, Code Snippets & Site Toolkit

Nexter Extension <= 4.4.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nxt-year' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-4.4.1

Correctif

4.4.2

Publication

01/12/2025

CVE-2023-45750 Moyenne · 6,1
Nexter Extension – Security, Performance, Code Snippets & Site Toolkit

Nexter Extension <= 2.0.3 – Reflected Cross-Site Scripting via post and post_id

The Nexter Extension plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post’ and 'post_id' parameters in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-2.0.3

Correctif

2.0.4

Publication

12/10/2023

CVE-2023-45751 Élevée · 7,2
Nexter Extension – Security, Performance, Code Snippets & Site Toolkit

Nexter Extension <= 2.0.3 – Authenticated(Editor+) Remote Code Execution via metabox

The Nexter Extension plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.3 via the nxt-code-php-snippet metabox. This allows authenticated attackers with editor-level privileges and above to execute code on the server.

Versions affectées

*-2.0.3

Correctif

2.0.4

Publication

12/10/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités