CVE-2026-16302: Spectra Legacy – Gutenberg Blocks <= 2.20.0 - Authenticated (Contributor+) Sensitive Information Exposure

Published Sep 24, 2026
·
Updated

The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editorassets function, which exposes the uaginstalinkedaccounts option through the uagbblocksinfo object without a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw Instagram Graph API access tokens configured by an administrator. Exploitation requires the Spectra Pro plugin to be active with a linked Instagram account.

Affected Software

1 affected component
Spectra Spectra Legacy – Gutenberg Blocks<=2.20.0

Event History

Sep 24, 2026
CVE Published
via MITRE·11:31 AM
Data Sourced
via MITRE·11:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to token disclosure?

Exposure requires Spectra Legacy – Gutenberg Blocks version 2.20.0 or earlier, with Spectra Pro active and an Instagram account linked by an administrator. Sites without an active Spectra Pro integration or linked Instagram account do not meet the stated exploitation conditions.

2

What access does an attacker need?

An attacker must be authenticated as a WordPress user with Contributor-level access or higher. No user interaction is required.

3

What information can be obtained?

A qualifying attacker can extract the uag_insta_linked_accounts option exposed through the uagb_blocks_info object. This can include raw Instagram Graph API access tokens configured by an administrator.

4

How can administrators assess whether they may already be affected?

Review whether users with Contributor or higher roles had access while the affected plugin version was installed, and determine whether Spectra Pro was active with a linked Instagram account. If those conditions existed, treat the configured Instagram Graph API token as potentially exposed.

5

What should be done if exposure is suspected?

Update beyond version 2.20.0. If a linked Instagram account was present while affected versions were in use, rotate its Instagram Graph API access token and review Contributor-and-higher accounts for unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203