CVE-2026-7465

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation requires a two-block payload embedded in post content: the first block registers a fake uagb/-prefixed block type with an attacker-specified render_callback, and the second block of the same fake type triggers invocation of that callback via call_user_func() during sequential block rendering in the same page request.
Configurations

No configuration.

History

22 Jul 2026, 06:10

Type Values Removed Values Added
Summary
  • (es) El plugin Spectra Gutenberg Blocks - Website Builder for the Block Editor para WordPress es vulnerable a ejecución remota de código en todas las versiones hasta, e incluyendo, la 2.19.25. Esto hace posible que atacantes autenticados, con acceso de nivel Colaborador y superior, ejecuten código en el servidor. La explotación requiere una carga útil de dos bloques incrustada en el contenido de la publicación: el primer bloque registra un tipo de bloque falso con prefijo uagb/ con un render_callback especificado por el atacante, y el segundo bloque del mismo tipo falso activa la invocación de esa devolución de llamada a través de call_user_func() durante la renderización secuencial de bloques en la misma solicitud de página.

30 May 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-30 10:16

Updated : 2026-07-22 06:10


NVD link : CVE-2026-7465

Mitre link : CVE-2026-7465

CVE.ORG link : CVE-2026-7465


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management