Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.41 - Authenticated (Subscriber+) Sensitive Information Exposure via Localized Plugin Settings

Medium 4.3 CWE-200Fixed in 5.1.0
ID
WPSEC-2026-0440
Plugin
Post Grid Gutenberg Blocks – PostX (ultimate-post)
Affected
from 2.9.10 before 5.1.0
Remediation
Update to 5.1.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites on WPSec AttackSurface
Fix released
Published

Description

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 2.9.10 to 5.0.41. The complete plugin settings, including the OpenAI API secret key saved for the ChatGPT addon, are output as script data on every WordPress dashboard page and in the block editor, whatever the user's role. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the site's OpenAI API key and use it at the site owner's expense. Exploitation requires an OpenAI API key to have been saved in the ChatGPT addon settings.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0