
🚨 Spectra Legacy に脆弱性(深刻度 中) 100万サイト以上が利用 / CVSS 4.3 修正版 2.20.1 が公開済み https://shindan.m-g-n.me/alerts/cve-2026-16302/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_assets function, which exposes the uag_insta_linked_accounts option through the uagb_blocks_info object without a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw Instagram Graph API access tokens configured by an administrator. Exploitation requires the Spectra Pro plugin to be active with a linked Instagram account.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🚨 Spectra Legacy に脆弱性(深刻度 中) 100万サイト以上が利用 / CVSS 4.3 修正版 2.20.1 が公開済み https://shindan.m-g-n.me/alerts/cve-2026-16302/