--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-10586

📛 CVE Title

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery

Description

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

Overview

State
PUBLISHED
Assigner (CNA)
Wordfence
CVSS severity
HIGH
CVSS score
CVSS 7.2 / 10 7.2 7.2 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Effective score
7.2 / 10 HIGH source: CNA overview
CWE(s)
CWE-918
Reserved
2026-06-01
Published
2026-06-04 23:28 UTC
Last updated
2026-06-05 01:59 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/10xxx/CVE-2026-10586.json
Linked Threat
CVE-2026-10586 — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-06-05 00:16:57 UTC
NVD last modified
2026-06-05 00:16:57 UTC
NVD CVSS v3.1
CVSS 7.2 / 10 7.2 7.2 / 10 HIGH source: security@wordfence.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Exploitability subscore
3.9 / 10
Impact subscore
2.7 / 10

NVD / KEV / EPSS data refreshed 2026-06-05 09:37 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-34771
Assigner
Wordfence
Published
Jun 4, 2026, 11:28:52 PM
Updated
Jun 5, 2026, 1:59:19 AM
EUVD base score (CVSS 3.1)
7.2 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
EUVD-reported EPSS
0.0000
Vendors
wpdevteam
Products
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns (0 ≤6.1.3)
Aliases
GHSA-5rm6-jpq7-cq95

ENISA description: The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

EUVD references (2)

Affected products (1)

VendorProductVersionsPlatforms
wpdevteam Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns 0 (affected)

Remediations (11)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • Wordfence remediation: Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
    Wordfence

    Update to version 6.1.4, or a newer patched version

    2026-06-05 13:17 UTC
  • web:cvetodo.com

    How do I fix CVE-2026-10586 ? To remediate CVE-2026-10586 : Check wpdevteam's security advisories for official patches and updates. Update Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns to the latest patched version. Review the references section below for vendor advisories and mitigation guidance.

    2026-06-05 10:33 UTC
  • web:cybersecuritynews.com

    Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.

    2026-06-05 10:33 UTC
  • web:hivepro.com

    Summary Microsoft's May 2026 Patch Tuesday security update addresses 137 critical vulnerabilities across the Microsoft product ecosystem, representing a significant security update for enterprise and consumer environments.

    2026-06-05 10:33 UTC
  • web:nvd.nist.gov

    Description Inappropriate implementation in Chromoting in Google Chrome prior to 148..7778.168 allowed a local attacker to bypass discretionary access control via a malicious file. (Chromium security severity: Medium)

    2026-06-05 10:33 UTC
  • web:blog.qualys.com

    May 2026's Patch Tuesday arrives with Microsoft addressing a fresh set of vulnerabilities across its ecosystem, reinforcing the ongoing need for timely patching in an increasingly threat-heavy…

    2026-06-05 10:33 UTC
  • web:thecyberexpress.com

    Microsoft has rolled out its May 2026 Patch Tuesday security updates, delivering fixes for approximately 120 vulnerabilities across Windows, Microsoft Office, networking services, and enterprise platforms.

    2026-06-05 10:33 UTC
  • web:www.pdq.com

    May 2026 Patch Tuesday is here, and PDQ is back with another recap. Will we see another month of increased CVE volume? Is AI to blame? Dive in to learn more.

    2026-06-05 10:33 UTC
  • web:www.thehackerwire.com

    TheHackerWire - Your daily source for cybersecurity news, CVE alerts, hacking tutorials, and security tool reviews. Stay ahead of cyber threats.

    2026-06-05 10:33 UTC
  • web:zecurit.com

    Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

    2026-06-05 10:33 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-06-05 10:33 UTC

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

MITRE references (2) cveawg.mitre.org

Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.

Web references (10)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search. Last searched: 2026-06-05 09:38 UTC.

  • Cybersecurity News & CVE Updates - CVEFeed Newsroom web:cvefeed.io

    Stay informed with the latest cybersecurity news, CVE updates, exploit reports, and security analysis from CVEFeed.

  • Latest CVE Vulnerabilities - CVEFeed web:cvefeed.io

    Browse the latest discovered CVE vulnerabilities with risk scoring, exploit data, and real-time security analytics from CVEFeed.

  • MS-Agent Vulnerability Let Attackers Hijack AI Agent to Gain Full ... web:cybersecuritynews.com

    A critical vulnerability was discovered in the MS-Agent framework, a tool that enables AI agents to perform autonomous tasks.

  • Current Common Vulnerabilities and Exposures - Feedly web:feedly.com

    Welcome to Feedly CVEs — Research critical vulnerabilities ( CVEs ) with all the real-time and historical information you need to assess the risk to your organization. This free resource uses Feedly's AI to synthesize and analyze vulnerability information from across the web, including estimating CVSS scores up to 3 days before it's reported to the NVD.

  • Nvd - Cve-2026-8586 web:nvd.nist.gov

    An official website of the United States government Here's how you know

  • Bloat Risk? Microsoft's Notepad Upgrade Also Introduced a Vulnerability ... web:www.pcmag.com

    Microsoft's effort to modernize the humble Notepad app has come with a cost: Security researchers have discovered a serious vulnerability in the program following a feature update. The flaw ...

  • CVE-2026-10586 - Vulnerability - TheHackerWire web:www.thehackerwire.com

    TheHackerWire - Your daily source for cybersecurity news, CVE alerts, hacking tutorials, and security tool reviews. Stay ahead of cyber threats.

  • CVE: Common Vulnerabilities and Exposures web:www.cve.org

    At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

  • Warning Issued About High-severity Flaw Affecting Microsoft Exchange ... web:www.hipaajournal.com

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Microsoft have issued warnings about a high-severity flaw affecting Exchange hybrid CISA and Microsoft have issued a warning about a high-severity elevation of privilege vulnerability in certain Microsoft Exchange hybrid deployments, which could be exploited undetected to compromise the Exchange Online service.

  • National Vulnerability Database | NIST web:www.nist.gov

    NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation's cybersecurity infrastructure.

NVD-tagged references (2)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (1)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cve CVE-2026-10586 no local data 2026-06-05 13:17 UTC

Flagged vendors

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2026-10586.json.

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-10586",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-05T01:59:09.608263Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-05T01:59:19.825Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Gutenberg Essential Blocks \u2013 Page Builder for Gutenberg Blocks & Patterns",
              "vendor": "wpdevteam",
              "versions": [
                {
                  "lessThanOrEqual": "6.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Shambles"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Gutenberg Essential Blocks \u2013 Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918 Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-04T23:28:52.002Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/08906577-162c-4875-b16c-18d4912c2611?source=cve"
            },
            {
              "url": "https://plugins.trac.wordpress.org/browser/essential-blocks/tags/6.1.3/includes/Integrations/AI/AI.php#L171"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-04-02T00:00:00.000Z",
              "value": "Discovered"
            },
            {
              "lang": "en",
              "time": "2026-06-01T19:42:41.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-06-04T10:40:13.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Gutenberg Essential Blocks \u2013 Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-10586",
        "datePublished": "2026-06-04T23:28:52.002Z",
        "dateReserved": "2026-06-01T19:26:38.526Z",
        "dateUpdated": "2026-06-05T01:59:19.825Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }