CVE-2025-15678

MEDIUM

Nexter Blocks < 5.0.2 - Author+ Stored XSS via SVG Upload

Title source: cna
STIX 2.1

Description

The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by default), allowing them to upload a file containing malicious JavaScript that executes when the file is accessed, leading to Stored Cross-Site Scripting.

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/2405c1ef-844a-462b-8329-c09d33b255b2/

Scores

CVSS v3 6.1
EPSS 0.0015
EPSS Percentile 4.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
None/Nexter Blocks < 5.0.2
Published Aug 06, 2026
Tracked Since Aug 06, 2026