CVE

CVE-2026-13154 — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 6.4.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13154 Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 6.4.0 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 6.4.0 6.4.0 2026-08-06

CVE-2026-13154

A vulnerability exists in Gutenberg Essential Blocks plugin versions prior to 6.4.0, where an attacker can exploit a flaw in how the plugin handles publicly viewable post types through its REST routes, effectively granting unauthorized access to certain published entries of custom post types that are supposed to be private. This occurs because the plugin fails to properly authenticate and authorize requests for these post types before retrieving their data.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.