CVE-2026-16302
Received Received - Intake

Sensitive Information Exposure in Spectra Legacy – Gutenberg Blocks Plugin

Vulnerability report for CVE-2026-16302, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: Wordfence

Description

The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_assets function, which exposes the uag_insta_linked_accounts option through the uagb_blocks_info object without a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw Instagram Graph API access tokens configured by an administrator. Exploitation requires the Spectra Pro plugin to be active with a linked Instagram account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
brainstormforce spectra_legacy_gutenberg_blocks to 2.20.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Spectra Legacy – Gutenberg Blocks WordPress plugin. It allows authenticated attackers with Contributor-level access or higher to access sensitive data, specifically raw Instagram Graph API access tokens configured by an administrator. This happens because the plugin exposes the uag_insta_linked_accounts option without proper capability checks.

Detection Guidance

To detect this vulnerability, check WordPress sites running the Spectra Legacy – Gutenberg Blocks plugin versions up to 2.20.0. Look for exposed uag_insta_linked_accounts option via the uagb_blocks_info object. Use commands like grep to search plugin files for 'editor_assets' or 'uagb_blocks_info' in the plugin directory.

Impact Analysis

If you use this plugin and have linked an Instagram account via Spectra Pro, an attacker could steal your Instagram Graph API access tokens. This could lead to unauthorized access to your Instagram account, data breaches, or misuse of connected services.

Compliance Impact

This vulnerability exposes raw Instagram Graph API access tokens, which could include sensitive user data. If tokens grant access to personal or health-related content, it may violate GDPR (data protection) or HIPAA (privacy for healthcare data) by unauthorized exposure of personal information.

Mitigation Strategies

Immediately update the Spectra Legacy – Gutenberg Blocks plugin to the latest version beyond 2.20.0. If using Spectra Pro, verify no linked Instagram accounts are exposed. Remove any unnecessary Contributor-level or higher accounts. Monitor for unauthorized access or data leaks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16302. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart