SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15420

MEDIUM · CVSS 4.3 EPSS 0.59%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

The Nexter Blocks plugin for WordPress is susceptible to a Directory Traversal vulnerability that allows authenticated attackers with subscriber-level access or higher to delete arbitrary JavaScript and CSS files on the server. This could result in denial of service or the destruction of essential plugin and theme assets. WordPress site administrators using this plugin should prioritize patching to mitigate potential disruptions and data loss.

CVE
CVE-2026-15420
Severity
MEDIUM
CVSS
4.3
EPSS
0.59%
WordPress

Original NVD Description

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary JS/CSS files on the server, which can lead to denial of service or destruction of critical plugin and theme assets.