CVE-2026-86783
Received Received - Intake

Post Metadata Disclosure in Post Grid Gutenberg Blocks

Vulnerability report for CVE-2026-86783, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending, scheduled and password-protected posts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
wp_the_post_grid the_post_grid_gutenberg_blocks to 5.0.41 (exc)
post_grid post_grid_gutenberg_blocks to 5.0.41 (exc)
postx postx to 5.0.41 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Post Grid Gutenberg Blocks WordPress plugin before version 5.0.41. It allows unauthenticated users to access a REST API route that reveals custom field key names of any post, including private, draft, pending, scheduled, or password-protected posts. The plugin fails to perform authorization or post-visibility checks, enabling unauthorized disclosure of sensitive metadata.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the Post Grid Gutenberg Blocks plugin version prior to 5.0.41. You can verify the plugin version in the WordPress admin panel under Plugins. Additionally, monitor network traffic for unauthorized requests to the vulnerable REST API route that may expose custom field keys.

Impact Analysis

Unauthenticated attackers could exploit this to gather information about custom fields in posts they should not access. This may reveal details about draft content, private posts, or protected posts, potentially aiding further attacks or data exfiltration. The impact is higher if sensitive data is stored in custom fields.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's confidentiality requirements. It may result in non-compliance due to unauthorized disclosure of personal or protected health information stored in custom fields.

Mitigation Strategies

Immediately update the Post Grid Gutenberg Blocks plugin to version 5.0.41 or later. If an update is not available, consider disabling the plugin temporarily until a patch is released. Ensure your WordPress site has proper access controls and restricts unauthenticated API access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86783. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart