What is CVE-2025-15678?
CVE-2025-15678 is a Stored Cross-Site Scripting vulnerability in the Nexter Blocks WordPress plugin before version 5.0.2, where the plugin fails to sanitize uploaded SVG files. This allows authenticated users with upload permissions to inject malicious JavaScript that executes when the file is accessed. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2025-15678, Nexter Blocks WordPress plagininin 5.0.2-dən əvvəlki versiyalarında aşkarlanmış Stored Cross-Site Scripting zəifliyidir. Plagin yüklənən SVG fayllarını sanitizə etmir, bu da autentifikasiyalı istifadəçilərə zərərli JavaScript kodu yerləşdirməyə imkan verir. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin is affected by CVE-2025-15678 and what is the cause?
CVE-2025-15678 is a Stored Cross-Site Scripting vulnerability affecting the Nexter Blocks WordPress plugin before version 5.0.2. The cause is that the plugin fails to sanitize uploaded SVG files.
What should I do to protect against CVE-2025-15678?
To protect against CVE-2025-15678, it is recommended to update the Nexter Blocks plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.