AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-13153

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Gutenberg Essential Blocks plugin for WordPress, prior to version 6.4.0, is vulnerable due to insufficient access controls on a public REST route, which exposes sensitive WooCommerce sales metrics to unauthenticated users. This flaw allows unauthorized individuals to retrieve the total sales figures for any published product, potentially leading to competitive disadvantage or data leakage. WordPress site administrators using this plugin should prioritize upgrading to the latest version to mitigate this risk.

CVE
CVE-2026-13153
Severity
HIGH
CVSS
7.5
EPSS
0.26%
WordPress

Original NVD Description

The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.