---
id: CVE-2025-15678
title: >-
  The Nexter Blocks  WordPress plugin before 5.0.2 does not sanitize uploaded
  SVG files and allows SVG uploads for any user able to upload files (Author by
  default), allowing them to upload a file containing malicious JavaScript that
  execu…
summary: >-
  The Nexter Blocks  WordPress plugin before 5.0.2 does not sanitize uploaded
  SVG files and allows SVG uploads for any user able to upload files (Author by
  default), allowing them to upload a file containing malicious JavaScript that
  execu…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-08-06'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T14:10:00.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15678'
references:
  - url: 'https://wpscan.com/vulnerability/2405c1ef-844a-462b-8329-c09d33b255b2/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00253
epssPercentile: 0.15106
ingestedAt: '2026-09-29T14:36:14.076Z'
---

## Overview

The Nexter Blocks  WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by default), allowing them to upload a file containing malicious JavaScript that executes when the file is accessed, leading to Stored Cross-Site Scripting.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
