GHSA-f7w9-vf85-gjj5MediumCVSS 5.3

The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization...

Published
September 23, 2026
Last Modified
September 23, 2026

🔗 CVE IDs covered (1)

📋 Description

The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending, scheduled and password-protected posts.

🔗 References (3)