Critical 9.8 Unfixed
2026-03-25≤ 1.1.1
CVE-2026-25429
Minimum safe version
1.1.1
Update to 1.1.1 or later to address 1 fixable vulnerability
CVE-2026-25429
Nexa Blocks <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps Widget
WordPress Nexa Blocks plugin <= 1.1.1 - Server Side Request Forgery (SSRF) vulnerability
WordPress Nexa Blocks plugin <= 1.1.0 - Cross Site Scripting (XSS) Vulnerability