CVE-2026-13153
Received Received - Intake

Unauthenticated Access to WooCommerce Sales Data in Gutenberg Essential Blocks

Vulnerability report for CVE-2026-13153, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WPScan

Description

The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpbeaverbuilder gutenberg_essential_blocks to 6.4.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Essential Blocks WordPress plugin versions before 6.4.0. It allows unauthenticated users to access a public REST route that exposes sensitive WooCommerce sales data by over-fetching a non-public metric, revealing the lifetime number of units sold for any published product.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the Gutenberg Essential Blocks plugin version prior to 6.4.0. You can verify the plugin version via the WordPress admin panel or by inspecting the plugin files. Use the REST API endpoint /wp-json/essential-blocks/v1/sales-metric to see if it returns WooCommerce sales data without authentication.

Impact Analysis

Unauthenticated attackers could access private sales data of products, potentially revealing business performance metrics or proprietary information. This could lead to competitive disadvantages or misuse of sensitive data.

Compliance Impact

This vulnerability may violate data protection regulations like GDPR or HIPAA by exposing sensitive sales data without authorization. Organizations could face legal penalties or reputational damage for failing to protect such information.

Mitigation Strategies

Immediately update the Gutenberg Essential Blocks plugin to version 6.4.0 or later. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Ensure your WordPress site is running the latest version and audit other plugins for similar issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13153. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart