What is CVE-2026-17011?
CVE-2026-17011 is a vulnerability in the Nexter Blocks WordPress plugin before version 5.0.2, where a REST endpoint improperly allows users with at least the Contributor role to save arbitrary global CSS. This can lead to site-wide defacement, content hiding, and UI redressing attacks. Immediate plugin update is required.
Azərbaycanca: CVE-2026-17011 Nexter Blocks WordPress plaginində kritik boşluqdur. 5.0.2 versiyasından əvvəlki versiyalarda REST endpoint vasitəsilə Contributor rolunda olan istifadəçilər qlobal CSS saxlaya bilir, bu isə sayt üzərində təhrif, məzmun gizlətmə və UI redressing hücumlarına yol açır. Plagin dərhal ən son versiyaya yenilənməlidir.
FAQ2
Which WordPress plugin is affected by CVE-2026-17011 and in which versions does it exist?
The CVE-2026-17011 vulnerability exists in the Nexter Blocks plugin in versions prior to 5.0.2.
What attacks can a user with the Contributor role carry out by exploiting CVE-2026-17011?
A user with the Contributor role can save global CSS through the REST endpoint, leading to site-wide defacement, content hiding, and UI redressing attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.