CVE-2026-10780
Last modified
CVE-2026-10780 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to the static_block_content() shortcode handler retrieving a post via get_post() using an attacker-supplied 'id' attribute and outputting its post_content without verifying the post's status (private, draft, pending) or the requesting user's capability to view it. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to the static_block_content() shortcode handler retrieving a post via get_post() using an attacker-supplied 'id' attribute and outputting its post_content without verifying the post's status (private, draft, pending) or the requesting user's capability to view it. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary posts, including private and draft static blocks (and any other post type) created by administrators, by embedding the [static_block_content id="X"] shortcode in their own content and previewing it.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-10780?
How severe is CVE-2026-10780?
How do I fix CVE-2026-10780?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10773The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsy…5.4
- CVE-2026-10774Zephyr's Bluetooth Mesh subnet key management leaks one PSA …6.5
- CVE-2026-10775A vulnerability was determined in sgl-project SGLang up to 0…5.3
- CVE-2026-10777A vulnerability was identified in ealpha072 Student-Manageme…7.3
- CVE-2026-10779The Classified Listing – Classified ads & Business Directory…4.3
- CVE-2026-1078An arbitrary file-write vulnerability in Pega Browser Extens…7.2
- CVE-2026-10782The RealHomes Memberships plugin for WordPress is vulnerable…4.3
- CVE-2026-10783A security flaw has been discovered in gradio-app gradio 6.1…2.5
- CVE-2026-10786Improper access control in the ticketing integration setting…6.5
- CVE-2026-10787Missing authorization in the deleted user groups API in Devo…4.3
- CVE-2026-10789A maliciously crafted webpage, when visited by a user with A…9.6
- CVE-2026-1079A native messaging host vulnerability in Pega Browser Extens…6
Are you affected by CVE-2026-10780?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
