CVE-2026-86783: Unknown Post Grid Gutenberg Blocks
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending, scheduled and password-protected posts.
Affected products
- Unknown Post Grid Gutenberg Blocks: before 5.0.41 (fixed in 5.0.41)
Published 2026-09-23. Last modified 2026-09-23.