CVE-2026-25429Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through <= 1.1.1.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-29); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-29: 2Mentions · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-09: 1Technical Details · 2026-03-29: 203-2904-09
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-292
Disclosure2
2026-04-091
PoC1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25429 Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through &lt;= 1.1.1. https://www.cve.org/CVERecord?id=CVE-2026-25429

    Post summary

    The text announces CVE‑2026‑25429, describing its deserialization flaw and affected versions, but does not provide PoC, exploit code, active exploitation evidence, patch details, or debunking claims.

    00010224
    56.9K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-25429-nexa-blocks-version-1-1-1-high-vulnerability-proof-of-concept CVE-2026-25429 #WordPress plugin #vulnerability nexa-blocks #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post links to a proof‑of‑concept for CVE‑2026‑25429 affecting the Nexa Blocks WordPress plugin, indicating a high‑severity issue but providing no further technical, exploitation, or mitigation details.

    0000047
    6 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25429 Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through &lt;= 1.1.1. https://www.cve.org/CVERecord?id=CVE-2026-25429 ----- Traducción: CVE-2026-25429 Deseria… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-25429, a deserialization vulnerability in Nexa Blocks that allows object injection, affecting versions up to 1.1.1.

    0000025
    65 followersView on X

Explore more