CVE-2026-86783: Unknown Post Grid Gutenberg Blocks

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending, scheduled and password-protected posts.

Affected products

  • Unknown Post Grid Gutenberg Blocks: before 5.0.41 (fixed in 5.0.41)

Published 2026-09-23. Last modified 2026-09-23.