The Spectra Gutenberg Blocks – Website Builder for the...
Moderate severity
Unreviewed
Published
Feb 3, 2026
to the GitHub Advisory Database
•
Updated Feb 3, 2026
Description
Published by the National Vulnerability Database
Feb 3, 2026
Published to the GitHub Advisory Database
Feb 3, 2026
Last updated
Feb 3, 2026
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.19.17. This is due to the plugin failing to check
post_password_required()before rendering post excerpts in therender_excerpt()function and theuagb_get_excerpt()helper function. This makes it possible for unauthenticated attackers to read excerpts of password-protected posts by simply viewing any page that contains a Spectra Post Grid, Post Masonry, Post Carousel, or Post Timeline block.References