Extension WordPress
Vulnérabilités Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder
Cette page rassemble les failles publiées pour Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder
11 fiches
Nexter Blocks <= 4.7.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'commentIcon' Block Attribute
The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due to insufficient input sanitization…
*-4.7.4
4.7.5
08/07/2026
Nexter Blocks <= 4.7.0 – Unauthenticated Information Exposure
The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.0. This makes it possible for unauthenticated attackers to extract…
*-4.7.0
4.7.1
26/03/2026
Nexter Blocks <= 4.6.3 – Authenticated (Subscriber+) Information Exposure
The Nexter Gutenberg Blocks – Website Builder & 1000+ Starter Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.6.3. This makes it possible for authenticated attackers, with Subscriber-level access…
*-4.6.3
4.6.4
26/01/2026
Nexter Blocks <= 4.5.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-4.5.4
4.5.5
18/08/2025
Nexter Blocks <= 4.5.4 – Missing Authorization
The Nexter Blocks – WordPress Gutenberg Blocks & 1000+ Starter Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.5.4. This makes…
*-4.5.4
4.5.5
14/08/2025
Nexter Blocks <= 4.0.7 – Missing Authorization
The Nexter Blocks – WordPress Gutenberg Blocks & 1000+ Starter Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.7. This makes…
*-4.0.7
4.0.8
03/01/2025
Nexter Blocks <= 4.0.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-4.0.4
4.0.5
30/12/2024
Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-4.3.1
4.3.2
03/12/2024
Nexter Blocks <= 3.3.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-3.3.3
4.0.0
24/10/2024
The Plus Blocks for Block Editor | Gutenberg <= 3.2.5 – Missing Authorization
The The Plus Blocks for Block Editor | Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the Tp_f_delete_transient() function in versions up to, and including, 3.2.5. This makes…
*-3.2.5
3.2.6
25/04/2024
The Plus Blocks for Block Editor | Gutenberg <= 3.2.5 – Reflected Cross-Site Scripting
The The Plus Blocks for Block Editor | Gutenberg plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.2.5
3.2.6
28/03/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.