๐Ÿ” CVE Alert

CVE-2026-86783

UNKNOWN 0.0

PostX < 5.0.41 - Unauthenticated Custom Field Key Disclosure via REST API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending, scheduled and password-protected posts.

Vendor unknown
Product post grid gutenberg blocks
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for unknown post grid gutenberg blocks

Be the first to know when new unknown vulnerabilities affecting unknown post grid gutenberg blocks are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Post Grid Gutenberg Blocks
0 < 5.0.41

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/719fc130-748b-4bad-8091-2858664299ed/

Credits

Pedro Pinho WPScan