PoC Index

CVE-2026-17011

LOW 3.8EPSS 0.1%

The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.

CVSS v3.1
3.8 LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
EPSS
0.12% chance of exploitation in the next 30 days, 2th percentile
Published
2026-08-09
Updated
2026-08-11

Proof-of-concept exploits (1)

References

Related