Executive brief
Nexter Blocks is a WordPress plugin used to build and design websites. A security flaw allows logged-in users with low-level permissions to delete important website files, such as those controlling the site's appearance and functionality. This can lead to the website becoming unavailable or appearing broken to visitors.
Technical details
The Nexter Blocks plugin for WordPress is vulnerable to directory traversal in all versions up to and including 5.0.0. The flaw exists within the 'plus_name' parameter in the tp-registered-blocks.php component, where insufficient input validation allows for path manipulation. An authenticated attacker with subscriber-level permissions or higher can exploit this to delete arbitrary JavaScript or CSS files on the server. This can result in a denial of service by destroying critical plugin or theme assets. A patch appears to be available in versions following 5.0.0.
Affected products
- posimyththemes Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder <= 5.0.0
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory
References
- https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.14/classes/tp-registered-blocks.php
- https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.14/classes/tp-registered-blocks.php
- https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.14/classes/tp-registered-blocks.php
- https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.14/classes/tp-registered-blocks.php
- https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.17/classes/tp-registered-blocks.php
- https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.17/classes/tp-registered-blocks.php
- https://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.17/classes/tp-registered-blocks.php