Description
The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_assets function, which exposes the uag_insta_linked_accounts option through the uagb_blocks_info object without a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw Instagram Graph API access tokens configured by an administrator. Exploitation requires the Spectra Pro plugin to be active with a linked Instagram account.
Published: 2026-09-24
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Information Exposure
Action: Apply Patch
AI Analysis

Impact

The Spectra Legacy – Gutenberg Blocks plugin contains a flaw that omits a capability check in the editor_assets function. This allows an authenticated user with Contributor level or higher to read the uag_insta_linked_accounts option from the uagb_blocks_info JavaScript object exposed to the editor. This reveals raw Instagram Graph API access tokens and related configuration data that an administrator has stored in WordPress. An attacker who can obtain these tokens can impersonate the account, read or modify Instagram data, and potentially perform further exploitations that depend on the confirmed ownership of the Instagram account. The vulnerability has a confidentiality impact but does not provide direct code execution, privilege escalation, or denial of service. The flaw is confined to the WordPress CMS and specifically the Spectra Legacy plugin; it cannot be leveraged by unauthenticated visitors.

Affected Systems

This issue affects the WordPress plugin Spectra Legacy – Gutenberg Blocks in all releases up to and including version 2.20.0. The vulnerability is only exploitable when the companion Spectra Pro plugin is active and an Instagram account is linked through that plugin, regardless of the WordPress installation’s configuration.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk level. The Exploit Prediction Scoring System score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests it has not been widely exploited in the wild. Potential attackers would need legitimate Contributor or higher privileges on the WordPress site and must have the Spectra Pro plugin enabled with an Instagram connection. The required attack vector is the web application layer, specifically by loading the editor page that serves the unprotected uagb_blocks_info payload. The combination of authentication requirements and plugin dependency reduces the overall likelihood, though the sensitivity of the data exposed elevates the importance of mitigation.

Generated by OpenCVE AI on September 24, 2026 at 12:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Spectra Legacy – Gutenberg Blocks plugin to the latest release (2.20.1 or newer) which implements the proper capability check for editor_assets.
  • If an update is not immediately possible, disable the Spectra Pro plugin or unlink the Instagram account until the patch is applied so that the uag_insta_linked_accounts data is no longer included in the editor payload.
  • Limit Contributor role capabilities or employ a role management plugin to prevent Contributors from accessing the Gutenberg editor where the data is exposed.

Generated by OpenCVE AI on September 24, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Brainstormforce
Brainstormforce spectra Legacy – Gutenberg Blocks
Wordpress
Wordpress wordpress
Vendors & Products Brainstormforce
Brainstormforce spectra Legacy – Gutenberg Blocks
Wordpress
Wordpress wordpress

Thu, 24 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_assets function, which exposes the uag_insta_linked_accounts option through the uagb_blocks_info object without a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw Instagram Graph API access tokens configured by an administrator. Exploitation requires the Spectra Pro plugin to be active with a linked Instagram account.
Title Spectra Legacy – Gutenberg Blocks <= 2.20.0 - Authenticated (Contributor+) Sensitive Information Exposure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Brainstormforce Spectra Legacy – Gutenberg Blocks
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-24T11:57:24.927Z

Reserved: 2026-07-20T13:12:38.874Z

Link: CVE-2026-16302

cve-icon Vulnrichment

Updated: 2026-09-24T11:57:19.383Z

cve-icon NVD

Status : Deferred

Published: 2026-09-24T12:17:11.637

Modified: 2026-09-24T14:40:36.103

Link: CVE-2026-16302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T12:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor