CVE-2026-13154
Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public.
| Vendor | unknown |
| Product | gutenberg essential blocks |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown gutenberg essential blocks
Be the first to know when new unknown vulnerabilities affecting unknown gutenberg essential blocks are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Gutenberg Essential Blocks
0 < 6.4.0
References
Credits
Muni Nitish Kumar Yaddala WPScan