Junglewise Threat Intelligence

CVE-2026-39516: POSIMYTH Nexter Blocks sensitive data exposure in WordPress plugin

CVE-2026-39516 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Technologies: POSIMYTH Innovations Nexter Blocks. Vendors: POSIMYTH Innovations.

Executive brief

Nexter Blocks is a popular WordPress plugin used to enhance the block editor with additional design elements. A vulnerability in versions up to 4.7.0 allows unauthorized individuals to access sensitive system information that should be restricted. This exposure could potentially reveal configuration details or other internal data, which attackers might use to facilitate further, more targeted attacks against the website.

Technical details

A 'Sensitive Data Exposure' vulnerability (CWE-497) exists in the POSIMYTH Nexter Blocks plugin (the-plus-addons-for-block-editor) for WordPress. The flaw allows an unauthenticated remote attacker to retrieve sensitive system information that is improperly exposed to an unauthorized control sphere. This occurs because the plugin fails to adequately restrict access to certain embedded data within the block editor environment. An attacker can exploit this by sending a crafted network request to the affected site, potentially gaining insights into the system configuration or other internal metadata. The issue is resolved in version 4.7.1.

Affected products

  • POSIMYTH Innovations Nexter Blocks (the-plus-addons-for-block-editor) <= 4.7.0

Timeline

  • 2026-02-24: disclosed: Reported by Bao - BlueRock
  • 2026-03-26: advisory: Patchstack published advisory
  • 2026-04-08: advisory: CVE published to NVD
  • 2026-04-08: patched: Version 4.7.1 released to address the vulnerability

References

Related threats