CVE-2026-15420: Posimyththemes Nexter Blocks – Gutenberg Blocks, Page Builder & Ai Website Builder

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary JS/CSS files on the server, which can lead to denial of service or destruction of critical plugin and theme assets.

Affected products

  • Posimyththemes Nexter Blocks – Gutenberg Blocks, Page Builder & Ai Website Builder: up to and including 5.0.0

Published 2026-07-24. Last modified 2026-07-24.