Junglewise Threat Intelligence

CVE-2026-15420: POSIMYTH Nexter Blocks directory traversal in plus_name parameter

CVE-2026-15420 · Severity: medium · CVSS 4.3 · Published 2026-07-24

Technologies: POSIMYTH Innovations Nexter Blocks. Vendors: POSIMYTH Innovations.

Executive brief

Nexter Blocks is a WordPress plugin used to build and design websites. A security flaw allows logged-in users with low-level permissions to delete important website files, such as those controlling the site's appearance and functionality. This can lead to the website becoming unavailable or appearing broken to visitors.

Technical details

The Nexter Blocks plugin for WordPress is vulnerable to directory traversal in all versions up to and including 5.0.0. The flaw exists within the 'plus_name' parameter in the tp-registered-blocks.php component, where insufficient input validation allows for path manipulation. An authenticated attacker with subscriber-level permissions or higher can exploit this to delete arbitrary JavaScript or CSS files on the server. This can result in a denial of service by destroying critical plugin or theme assets. A patch appears to be available in versions following 5.0.0.

Affected products

  • posimyththemes Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder <= 5.0.0

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References

Related threats