PT-2026-45089 · WordPress · Spectra Gutenberg Blocks

·

CVE-2026-7465

·

Published

2026-05-30

·

Updated

2026-06-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spectra Gutenberg Blocks – Website Builder for the Block Editor versions prior to 2.19.26
Description Authenticated attackers with Contributor-level access and above can achieve Remote Code Execution on the server. This is possible through a two-block payload embedded in post content. The first block registers a fake uagb/-prefixed block type with an attacker-specified render callback, and the second block of the same fake type triggers the invocation of that callback via the call user func() function during sequential block rendering in the same page request. This issue has been exploited in the wild.
Recommendations Update to a version newer than 2.19.25.

Fix

RCE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7465

Affected Products

Spectra Gutenberg Blocks