Medium 5.3
2026-04-08< 4.7.1
CVE-2026-39516
Minimum safe version
4.7.1
Update to 4.7.1 or later to address 9 fixable vulnerabilities
CVE-2026-39516
Nexter Blocks <= 4.6.3 - Authenticated (Subscriber+) Information Exposure
Nexter Blocks <= 4.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
CVE-2025-54739
CVE-2024-56294
WordPress Nexter Blocks Plugin <= 4.0.4 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-50452
CVE-2024-33572
CVE-2024-30435