PT-2026-5775 · WordPress · Spectra Gutenberg Blocks
Johska
·
Published
2026-02-03
·
Updated
2026-02-03
·
CVE-2026-0950
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress versions prior to 2.19.18
Description
The Spectra Gutenberg Blocks plugin for WordPress is susceptible to information disclosure. The plugin does not verify
post password required() before rendering post excerpts using the render excerpt() function and the uagb get excerpt() helper function. This allows unauthenticated attackers to view excerpts of password-protected posts through Spectra Post Grid, Post Masonry, Post Carousel, or Post Timeline blocks.Recommendations
Update to version 2.19.18 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spectra Gutenberg Blocks