{
 "id": "WPSEC-2026-0440",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0440/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0440/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0440/index.md",
 "title": "Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.41 - Authenticated (Subscriber+) Sensitive Information Exposure via Localized Plugin Settings",
 "description": "The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 2.9.10 to 5.0.41. The complete plugin settings, including the OpenAI API secret key saved for the ChatGPT addon, are output as script data on every WordPress dashboard page and in the block editor, whatever the user's role. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the site's OpenAI API key and use it at the site owner's expense. Exploitation requires an OpenAI API key to have been saved in the ChatGPT addon settings.",
 "plugin": {
  "slug": "ultimate-post",
  "name": "Post Grid Gutenberg Blocks for News, Magazines, Blog Websites",
  "full_name": "Post Grid Gutenberg Blocks – PostX",
  "wordpress_org": "https://wordpress.org/plugins/ultimate-post/",
  "advisories_url": "https://wpsec.com/vuln/plugin/ultimate-post/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/ultimate-post"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.9.10",
    "from_inclusive": true,
    "to": "5.1.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.9.10 before 5.1.0"
  ]
 },
 "introduced_in": "2.9.10",
 "fixed_in": "5.1.0",
 "remediation": "Update to 5.1.0 or later.",
 "fix_released": "2026-10-04T09:06:16+00:00",
 "published": "2026-10-06T14:47:47+00:00",
 "updated": "2026-10-06T14:18:53.003013+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0440/",
  "https://plugins.svn.wordpress.org/ultimate-post/tags/5.1.0/",
  "https://wordpress.org/plugins/ultimate-post/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/ultimate-post",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-06"
 }
}