Stored Cross-Site Scripting in Nexter Blocks WordPress Plugin by Nexter
CVE-2025-15678
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 6 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2025-15678?
The Nexter Blocks WordPress plugin, prior to version 5.0.2, permits users with file upload capabilities to upload SVG files without proper sanitization. This oversight allows these users to execute malicious JavaScript embedded within the SVG files, leading to stored cross-site scripting (XSS) vulnerabilities. When these files are accessed, the malicious script runs, potentially compromising user sessions and exposing sensitive information.
Affected Version(s)
Nexter Blocks 0 < 5.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.