CVE-2026-6394
The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due to the import_demo() function accepting a user-supplied URL in the demo_json_file POST parameter and passing it directly to wp_remote_get() without any URL validation or restriction against internal or private network destinations. The nexa_blocks_nonce required for the AJAX action is publicly expos
- Vendor
- wpdive
- Product
- Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
- Provider severity
- MEDIUM
- Conflicts
- 0