# Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.41 - Authenticated (Subscriber+) Sensitive Information Exposure via Localized Plugin Settings

- **ID:** WPSEC-2026-0440
- **Plugin:** Post Grid Gutenberg Blocks – PostX (`ultimate-post`), https://wordpress.org/plugins/ultimate-post/
- **Affected versions:** from 2.9.10 before 5.1.0
- **Fixed in:** 5.1.0 (Update to 5.1.0 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/ultimate-post
- **Fix released:** 2026-10-04
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0440/

## Description

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 2.9.10 to 5.0.41. The complete plugin settings, including the OpenAI API secret key saved for the ChatGPT addon, are output as script data on every WordPress dashboard page and in the block editor, whatever the user's role. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the site's OpenAI API key and use it at the site owner's expense. Exploitation requires an OpenAI API key to have been saved in the ChatGPT addon settings.

## References

- https://wpsec.com/vuln/WPSEC-2026-0440/
- https://plugins.svn.wordpress.org/ultimate-post/tags/5.1.0/
- https://wordpress.org/plugins/ultimate-post/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0440/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
