CVE-2026-15420
The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all ver
CVSS
4.3
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 24, 2026 · Last modified: Jul 24, 2026 · CWE-22
Not enough EPSS history yet.
The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary JS/CSS files on the server, which can lead to denial of service or destruction of critical plugin and theme assets.
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.14/classes/tp-registered-blocks.php#L2710
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.14/classes/tp-registered-blocks.php#L2862
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.14/classes/tp-registered-blocks.php#L2985
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.14/classes/tp-registered-blocks.php#L3521
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.17/classes/tp-registered-blocks.php#L2710
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.17/classes/tp-registered-blocks.php#L2862
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.17/classes/tp-registered-blocks.php#L2985
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/the-plus-addons-for-block-editor/tags/4.7.17/classes/tp-registered-blocks.php#L3521
- plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/changeset?reponame=&old=3614203%40the-plus-addons-for-block-editor&new=3614203%40the-plus-addons-for-block-editor
- www.wordfence.comhttps://www.wordfence.com/threat-intel/vulnerabilities/id/85550779-fd46-4130-92f1-b291d4e86b21?source=cve
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-167676.5 MED—
——0A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. Performing a manipulation of the argument entryName results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.18hCVE-2026-656947.5 HIG—
——0Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthenticated HTTP GET request exploiting the failure of normalize_path() to strip traversal sequences, disclosing sensitive files such as environment configuration files containing credentials and system files.19hCVE-2026-47669——
——0DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes files anywhere on the filesystem. In the default Docker deployment, DbGate runs as root and the `none` auth provider issues JWT tokens without credentials via `POST /auth/login`, so this is exploitable by any network-adjacent attacker. Version 7.1.9 fixes the issue.12hCVE-2026-156872.4 LOW—
——0A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false.21hCVE-2026-659204.3 MED—
——0Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or absolute paths in weight_map entries to escape the model directory and read safetensors files outside the intended location during model loading.22hCVE-2026-659197.5 HIG—
——0Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. Attackers can supply absolute paths or traversal sequences in the file parameter to read arbitrary files from the host filesystem without authentication.23h