Executive brief
The Nexa Blocks plugin for WordPress, which provides page-building tools for the Gutenberg editor, contains a security flaw that allows unauthorized individuals to make requests through the website's server. This could allow an attacker to access sensitive internal information, such as cloud service credentials or private network data, that is normally protected from the public internet. Because the security token required to trigger this action is accidentally exposed to all visitors, even unauthenticated users can exploit this vulnerability.
Technical details
The Nexa Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via the import_demo() function. This function accepts a user-supplied URL through the 'demo_json_file' POST parameter and passes it to wp_remote_get() without validation against internal or private network ranges. Although the action requires a nonce, the 'nexa_blocks_nonce' is leaked to all frontend visitors via wp_localize_script, effectively bypassing authentication requirements. Attackers can use this to probe internal services, access cloud metadata endpoints (like AWS IMDS), or chain requests by providing a malicious JSON file containing secondary image URLs that the server will also fetch.
Affected products
- Nexa Blocks Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Up to and including 1.1.1
Timeline
- 2026-05-20: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/nexa-blocks/tags/1.1.1/inc/classes/enqueue-assets.php
- https://plugins.trac.wordpress.org/browser/nexa-blocks/tags/1.1.1/inc/template/template.php
- https://plugins.trac.wordpress.org/browser/nexa-blocks/tags/1.1.1/inc/template/template.php
- https://plugins.trac.wordpress.org/browser/nexa-blocks/trunk/inc/classes/enqueue-assets.php
- https://plugins.trac.wordpress.org/browser/nexa-blocks/trunk/inc/template/template.php
- https://plugins.trac.wordpress.org/browser/nexa-blocks/trunk/inc/template/template.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/b4bb3067-7953-466d-a469-8a101450f133?source=cve