Executive brief
Nexter Blocks is a popular WordPress plugin used to build and design website pages. A security flaw allows users with basic contributor-level access to inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'commentIcon' parameter within the tp-post-meta component. This vulnerability allows authenticated attackers with contributor-level permissions or higher to inject arbitrary web scripts into a page. Because the scripts are stored on the server, they will execute in the context of any user's browser session when they visit the compromised page. The issue is addressed in versions following 4.7.4.
Affected products
- posimyththemes Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder <= 4.7.4
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory