Sensitive Data Exposure in POSIMYTH Nexter Blocks by The Plus Addons for Block Editor
CVE-2026-39516

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
8 April 2026

What is CVE-2026-39516?

This vulnerability in POSIMYTH Nexter Blocks allows unauthorized retrieval of embedded sensitive data, potentially compromising user confidentiality. It affects versions of Nexter Blocks from n/a to 4.7.0, indicating a significant risk for sites utilizing this block editor plugin. Users are advised to update their plugins to the latest version to mitigate exposure.

Affected Version(s)

Nexter Blocks 0 <= 4.7.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bao - BlueRock | Patchstack Bug Bounty Program
.