The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending, scheduled and password-protected posts.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending, scheduled and password-protected posts. | |
| Title | PostX < 5.0.41 - Unauthenticated Custom Field Key Disclosure via REST API | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:55:10.369Z
Reserved: 2026-09-08T11:48:34.198Z
Link: CVE-2026-86783
Updated: 2026-09-23T10:35:19.999Z
Status : Received
Published: 2026-09-23T06:17:04.130
Modified: 2026-09-23T11:17:14.857
Link: CVE-2026-86783
No data.
OpenCVE Enrichment
No data.
Weaknesses