CVE-2026-16302: Spectra Legacy – Gutenberg Blocks <= 2.20.0 - Authenticated (Contributor+) Sensitive Information Exposure
The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editorassets function, which exposes the uaginstalinkedaccounts option through the uagbblocksinfo object without a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw Instagram Graph API access tokens configured by an administrator. Exploitation requires the Spectra Pro plugin to be active with a linked Instagram account.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed to token disclosure?
Exposure requires Spectra Legacy – Gutenberg Blocks version 2.20.0 or earlier, with Spectra Pro active and an Instagram account linked by an administrator. Sites without an active Spectra Pro integration or linked Instagram account do not meet the stated exploitation conditions.
What access does an attacker need?
An attacker must be authenticated as a WordPress user with Contributor-level access or higher. No user interaction is required.
What information can be obtained?
A qualifying attacker can extract the uag_insta_linked_accounts option exposed through the uagb_blocks_info object. This can include raw Instagram Graph API access tokens configured by an administrator.
How can administrators assess whether they may already be affected?
Review whether users with Contributor or higher roles had access while the affected plugin version was installed, and determine whether Spectra Pro was active with a linked Instagram account. If those conditions existed, treat the configured Instagram Graph API token as potentially exposed.
What should be done if exposure is suspected?
Update beyond version 2.20.0. If a linked Instagram account was present while affected versions were in use, rotate its Instagram Graph API access token and review Contributor-and-higher accounts for unauthorized access.