Extension WordPress

Vulnérabilités Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

Cette page rassemble les failles publiées pour Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

11Vulnérabilités
0Critiques
11Avec correctif
6,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

11 fiches

CVE-2026-6740 Moyenne · 6,4
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

Nexter Blocks <= 4.7.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'commentIcon' Block Attribute

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due to insufficient input sanitization…

Versions affectées

*-4.7.4

Correctif

4.7.5

Publication

08/07/2026

CVE-2026-39516 Moyenne · 5,3
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

Nexter Blocks <= 4.7.0 – Unauthenticated Information Exposure

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.0. This makes it possible for unauthenticated attackers to extract…

Versions affectées

*-4.7.0

Correctif

4.7.1

Publication

26/03/2026

CVE-2026-24377 Moyenne · 4,3
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

Nexter Blocks <= 4.6.3 – Authenticated (Subscriber+) Information Exposure

The Nexter Gutenberg Blocks – Website Builder & 1000+ Starter Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.6.3. This makes it possible for authenticated attackers, with Subscriber-level access…

Versions affectées

*-4.6.3

Correctif

4.6.4

Publication

26/01/2026

CVE-2025-8567 Moyenne · 6,4
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

Nexter Blocks <= 4.5.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

Versions affectées

*-4.5.4

Correctif

4.5.5

Publication

18/08/2025

CVE-2024-56246 Moyenne · 6,4
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

Nexter Blocks <= 4.0.4 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-4.0.4

Correctif

4.0.5

Publication

30/12/2024

CVE-2024-5020 Moyenne · 6,4
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

Versions affectées

*-4.3.1

Correctif

4.3.2

Publication

03/12/2024

CVE-2024-50452 Moyenne · 6,4
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

Nexter Blocks <= 3.3.3 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-3.3.3

Correctif

4.0.0

Publication

24/10/2024

CVE-2024-33572 Moyenne · 4,3
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

The Plus Blocks for Block Editor | Gutenberg <= 3.2.5 – Missing Authorization

The The Plus Blocks for Block Editor | Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the Tp_f_delete_transient() function in versions up to, and including, 3.2.5. This makes…

Versions affectées

*-3.2.5

Correctif

3.2.6

Publication

25/04/2024

CVE-2024-30435 Moyenne · 6,1
Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder

The Plus Blocks for Block Editor | Gutenberg <= 3.2.5 – Reflected Cross-Site Scripting

The The Plus Blocks for Block Editor | Gutenberg plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-3.2.5

Correctif

3.2.6

Publication

28/03/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités