CyberRota Analysis
AI-GeneratedThe Gutenberg Essential Blocks plugin for WordPress, prior to version 6.4.0, is vulnerable due to insufficient access controls on a public REST route, which exposes sensitive WooCommerce sales metrics to unauthenticated users. This flaw allows unauthorized individuals to retrieve the total sales figures for any published product, potentially leading to competitive disadvantage or data leakage. WordPress site administrators using this plugin should prioritize upgrading to the latest version to mitigate this risk.
Original NVD Description
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.