---
id: CVE-2026-17011
title: >-
  The Nexter Blocks  WordPress plugin before 5.0.2 does not restrict who can
  save global CSS through one of its REST endpoints, allowing users with at
  least the Contributor role to store arbitrary CSS that is rendered site-wide
  on the fron…
summary: >-
  The Nexter Blocks  WordPress plugin before 5.0.2 does not restrict who can
  save global CSS through one of its REST endpoints, allowing users with at
  least the Contributor role to store arbitrary CSS that is rendered site-wide
  on the fron…
severity: none
published: '2026-08-09'
updated: '2026-08-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-17011'
references:
  - url: 'https://wpscan.com/vulnerability/a702e5cb-0fb3-419e-81df-fa5b26c81402/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.0017
epssPercentile: 0.05585
ingestedAt: '2026-08-09T15:33:38.106Z'
---

## Overview

The Nexter Blocks  WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
