Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 24 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brainstormforce
Brainstormforce spectra Legacy – Gutenberg Blocks Wordpress Wordpress wordpress |
|
| Vendors & Products |
Brainstormforce
Brainstormforce spectra Legacy – Gutenberg Blocks Wordpress Wordpress wordpress |
Thu, 24 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_assets function, which exposes the uag_insta_linked_accounts option through the uagb_blocks_info object without a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw Instagram Graph API access tokens configured by an administrator. Exploitation requires the Spectra Pro plugin to be active with a linked Instagram account. | |
| Title | Spectra Legacy – Gutenberg Blocks <= 2.20.0 - Authenticated (Contributor+) Sensitive Information Exposure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-24T11:57:24.927Z
Reserved: 2026-07-20T13:12:38.874Z
Link: CVE-2026-16302
Updated: 2026-09-24T11:57:19.383Z
Status : Received
Published: 2026-09-24T12:17:11.637
Modified: 2026-09-24T12:17:11.637
Link: CVE-2026-16302
No data.
OpenCVE Enrichment
Updated: 2026-09-24T12:30:18Z