๐Ÿ” CVE Alert

CVE-2026-13153

UNKNOWN 0.0

Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.

Vendor unknown
Product gutenberg essential blocks
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown gutenberg essential blocks

Be the first to know when new unknown vulnerabilities affecting unknown gutenberg essential blocks are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Gutenberg Essential Blocks
0 < 6.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/0401a229-9630-49ab-ae4b-53360cf5d109/

Credits

Revanth Hari Narayana Matte WPScan