CVE-2026-39516 is an information disclosure vulnerability affecting POSIMYTH Nexter Blocks (a WordPress block editor plugin) through version 4.7.0, which allows unauthorized users to retrieve embedded sensitive system data. The flaw stems from an exposure of sensitive information to an unauthorized control sphere, enabling attackers to access confidential data without proper authentication. This vulnerability impacts all installations of the affected plugin versions without restrictions. The vulnerability carries a CVSS score of 5.3 (Medium severity) with a network-based attack vector that requires no special access privileges or user interaction, making it relatively easy to exploit remotely. However, the impact is limited to confidentiality breaches, with no capability to modify or disrupt system availability. The EPSS score of 0.00036 indicates minimal probability of exploitation in the wild currently. There is no evidence of active exploitation or public exploit code availability at this time. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and remains inactive on threat tracking systems, suggesting limited real-world weaponization. While the medium CVSS score warrants attention, the low community engagement and absence of exploitation data indicate this is not currently a priority threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 4.7.0CPE match | cpe:2.3:a:posimyth:nexter_blocks:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.