What the vulnerability does
01Description
Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.22.
Explanation of Vulnerability in Simple Terms
02Summary
Spectra versions up to 2.19.22 lack proper authorization checks, allowing authenticated users with low privileges to read sensitive data they should not access. The vulnerability requires a valid user account but no special interaction. A site admin should update Spectra to a version newer than 2.19.22 to close this access control gap.
What an attacker can do
03Attacker Capabilities
Read sensitive data belonging to other users or restricted areas of the site.
Potential impact on your site
04Site Impact
Authenticated users can view confidential information they lack permission to access.
Conditions required to exploit
05Prerequisites
Attacker must have a valid low-privilege user account on the site.
Key dates
06Disclosure timeline
April 29, 2026
CVE published
May 12, 2026
Record updated