CVE-2026-13154: Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13154?
CVE-2026-13154 has a risk rating of 45, indicating a moderate severity level.
How do I fix CVE-2026-13154?
To fix CVE-2026-13154, update the Essential Blocks plugin to version 6.4.0 or later.
What type of data is exposed due to CVE-2026-13154?
CVE-2026-13154 allows unauthenticated users to read custom post type entries that are otherwise non-public.
Which software is affected by CVE-2026-13154?
CVE-2026-13154 affects the Essential Blocks plugin for WordPress prior to version 6.4.0.
Can unauthenticated users exploit CVE-2026-13154?
Yes, CVE-2026-13154 can be exploited by unauthenticated users to access restricted content.