CVE-2025-15678
Received Received - Intake

Stored XSS in Nexter Blocks WordPress Plugin

Vulnerability report for CVE-2025-15678, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WPScan

Description

The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by default), allowing them to upload a file containing malicious JavaScript that executes when the file is accessed, leading to Stored Cross-Site Scripting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nexter_blocks plugin 5.0.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Nexter Blocks WordPress plugin before version 5.0.2 has a vulnerability where it does not properly sanitize uploaded SVG files. This allows users with upload permissions, such as Authors, to upload SVG files containing malicious JavaScript. When these files are accessed, the embedded script executes, resulting in a Stored Cross-Site Scripting (XSS) attack.

Detection Guidance

Check for unauthorized SVG file uploads in WordPress directories, particularly in the uploads folder. Look for files with .svg extension that contain JavaScript code or unusual content. Review user roles with upload permissions like Authors.

Impact Analysis

This vulnerability can allow attackers to inject malicious scripts into your WordPress site. If exploited, it could lead to unauthorized actions on behalf of users, theft of sensitive data, or defacement of your website. Users with Author privileges or higher could upload malicious files.

Compliance Impact

This vulnerability could lead to data breaches, which may violate GDPR or HIPAA requirements for protecting user data. A successful XSS attack could expose personal or health information, resulting in non-compliance with these regulations and potential legal consequences.

Mitigation Strategies

Update the Nexter Blocks plugin to version 5.0.2 or later immediately. Remove any suspicious SVG files from the uploads directory. Restrict file upload permissions to only trusted users and disable SVG uploads if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15678. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart