What is CVE-2026-13154?
The Gutenberg Essential Blocks plugin for WordPress before version 6.4.0 contains an authorization bypass vulnerability in its REST API, allowing unauthenticated users to retrieve published entries from custom post types not intended to be publicly viewable. Users should immediately update the plugin to version 6.4.0 to mitigate the risk of unauthorized data exposure.
Azərbaycanca: Gutenberg Essential Blocks WordPress plaginində, 6.4.0 versiyasından əvvəlki versiyalarda, autentifikasiya olunmamış istifadəçilərə qeyri-ictimai 'custom post type' qeydlərini oxumağa imkan verən REST API zəifliyi aşkarlanıb. Bu zəiflik, təcavüzkarın gizli saxlanılması nəzərdə tutulan məlumatlara çıxış əldə etməsinə səbəb ola bilər; plagini dərhal 6.4.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Gutenberg Essential Blocks plugin are affected by CVE-2026-13154?
This vulnerability affects the Gutenberg Essential Blocks plugin for WordPress versions prior to 6.4.0.
What type of data can an attacker access by exploiting CVE-2026-13154?
An unauthenticated attacker can read published entries from custom post types that are not intended to be publicly viewable via the REST API.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.