CVE-2026-13153 - Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint
CVE ID :CVE-2026-13153
Published : Aug. 6, 2026, 6 a.m. | 1 hour, 9 minutes ago
Description :The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 6, 2026, 6 a.m. | 1 hour, 9 minutes ago
Description :The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...