Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39516

21
FAUCET Score

CVE-2026-39516 is an information disclosure vulnerability affecting POSIMYTH Nexter Blocks (a WordPress block editor plugin) through version 4.7.0, which allows unauthorized users to retrieve embedded sensitive system data. The flaw stems from an exposure of sensitive information to an unauthorized control sphere, enabling attackers to access confidential data without proper authentication. This vulnerability impacts all installations of the affected plugin versions without restrictions. The vulnerability carries a CVSS score of 5.3 (Medium severity) with a network-based attack vector that requires no special access privileges or user interaction, making it relatively easy to exploit remotely. However, the impact is limited to confidentiality breaches, with no capability to modify or disrupt system availability. The EPSS score of 0.00036 indicates minimal probability of exploitation in the wild currently. There is no evidence of active exploitation or public exploit code availability at this time. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and remains inactive on threat tracking systems, suggesting limited real-world weaponization. While the medium CVSS score warrants attention, the low community engagement and absence of exploitation data indicate this is not currently a priority threat.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, <= 4.7.0CPE match
cpe:2.3:a:posimyth:nexter_blocks:*:*:*:*:*:wordpress:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 6th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

patchstack.com / database/Wordpress/Plugin/the-plus-addons-for-block-editor/vulnerability/wordpress-nexter-blocks-plugin-4-7-0-sensitive-data-exposure-vulnerability