What is CVE-2026-15827?
The GutenKit Blocks plugin up to version 2.4.12 contains a missing capability check on specific REST API endpoints, leading to unauthorized data access. This vulnerability allows unauthenticated attackers to retrieve sensitive Mailchimp lists and interests data. Updating the plugin to the latest version is strongly advised.
Azərbaycanca: GutenKit Blocks plugininin 2.4.12 və daha əvvəlki versiyalarında REST API endpointlərində capability check çatışmazlığı aşkarlanıb. Bu boşluq autentifikasiya olunmamış şəxslərə Mailchimp siyahıları və maraq qrupları kimi həssas məlumatlara icazəsiz giriş imkanı verir. Pluginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the GutenKit Blocks plugin are affected by CVE-2026-15827?
This vulnerability affects the GutenKit Blocks plugin up to version 2.4.12.
What type of data can be accessed through the CVE-2026-15827 vulnerability?
This vulnerability allows unauthenticated attackers to retrieve sensitive Mailchimp lists and interests data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.