๐Ÿ” CVE Alert

CVE-2026-13154

UNKNOWN 0.0

Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public.

Vendor unknown
Product gutenberg essential blocks
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown gutenberg essential blocks

Be the first to know when new unknown vulnerabilities affecting unknown gutenberg essential blocks are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Gutenberg Essential Blocks
0 < 6.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/ab60ebee-c8b5-4bba-8138-2083ca14546a/

Credits

Muni Nitish Kumar Yaddala WPScan