CVE-2025-11369
Essential Blocks <= 5.7.2 - Missing Authorization To Authenticated (Author+) Information Disclosure
mediumMissing Authorization
4.3
CVSS Score
4.3
CVSS Score
medium
Severity
5.7.3
Patched in
57d
Time to patch
Description
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capability checks on the get_instagram_access_token_callback, google_map_api_key_save_callback and get_siteinfo functions in all versions up to, and including, 5.7.2. This makes it possible for authenticated attackers, with Author-level access and above, to view API keys configured for the external services.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NAttack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Low
Confidentiality
None
Integrity
None
Availability
Technical Details
Affected versions
<=5.7.2PublishedDecember 16, 2025
Last updatedFebruary 11, 2026
Affected pluginessential-blocks
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.