The Nexter Blocks plugin for WordPress has a security issue that affects versions up to 4.0.4. This means that it is possible for attackers who have contributor-level access or higher to add harmful web scripts to pages that will run when a user visits them.