| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-0726 | Nexter Extension – Site Enhancements Toolkit <= 4.4.6 - Unauthenticated PHP Object Injection via 'nxt_unserialize_replace' | posimyththemes | Nexter Extension – Security, Performance, Code Snippets & Site Toolkit | High | 8.1 | 2026-01-20 14:26:31 | Deep Dive |
| CVE-2025-13731 | Nexter Extension <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | posimyththemes | Nexter Extension – Security, Performance, Code Snippets & Site Toolkit | Medium | 6.4 | 2025-12-02 13:53:25 | Deep Dive |
| CVE-2023-45751 | WordPress Nexter Extension Plugin <= 2.0.3 is vulnerable to Remote Code Execution (RCE) | POSIMYTH | Nexter Extension | Critical | 9.1 | 2023-12-29 09:03:00 | Deep Dive |
| CVE-2023-45750 | WordPress Nexter Extension Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS) | POSIMYTH | Nexter Extension | High | 7.1 | 2023-10-24 11:28:01 | Deep Dive |