Impact
The Post Grid Gutenberg Blocks WordPress plugin fails to apply an authorization check on a REST API route that returns custom field key names for any post. As a result, anyone who can reach the site’s REST endpoint can retrieve the key names of private, draft, pending, scheduled, and password‑protected posts. The disclosure does not directly grant control of the site but exposes structural information that an attacker could use to craft more targeted attacks later. This flaw is identified as an information‑disclosure weakness (CWE‑200).
Affected Systems
All installations of the Post Grid Gutenberg Blocks plugin older than version 5.0.41 are affected. The vulnerability exists in WordPress sites that have the plugin loaded and have not disabled the associated REST API route. No other product or version is mentioned.
Risk and Exploitability
According to the CVSS scoring, the vulnerability has a score of 5.3, indicating moderate severity. The EPSS score of less than 1% shows a very low probability of exploitation at this time, and the CVE is not listed in the CISA KEV catalog. Attackers only need network access to the REST API endpoint; no authentication is required. The primary impact is the exposure of internal field names, which can aid in reconnaissance but does not provide direct control over the system.
OpenCVE Enrichment