CVE-2026-13153
Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.
| Vendor | unknown |
| Product | gutenberg essential blocks |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown gutenberg essential blocks
Be the first to know when new unknown vulnerabilities affecting unknown gutenberg essential blocks are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Gutenberg Essential Blocks
0 < 6.4.0
References
Credits
Revanth Hari Narayana Matte WPScan