CVE-2026-102002
Received Received - Intake

Sensitive Information Exposure in Otter Blocks WordPress Plugin

Vulnerability report for CVE-2026-102002, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Wordfence

Description

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.6 via the 'otter_form_widget_filter' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the email addresses of the five most recent form submitters, their submission dates, and the site's total form submission count. The widget is registered whenever the themeisle_blocks_form_emails option is non-empty β€” the normal state after any Form block has been saved β€” meaning the exposure is active on any standard site using the plugin's form feature.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
themeisle otter_blocks to 3.2.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Otter Blocks WordPress plugin allows authenticated users with subscriber-level access or higher to extract sensitive information from form submissions. The flaw exists in versions up to 3.2.6 and exposes email addresses of the five most recent form submitters, their submission dates, and the total form submission count.

Detection Guidance

This vulnerability can be detected by checking if the Otter Blocks plugin is installed and active on your WordPress site. Look for the presence of the 'otter_form_widget_filter' parameter in requests. Use commands like 'grep -r "otter_form_widget_filter" /path/to/wordpress/' to search for references in plugin files.

Impact Analysis

Attackers could misuse exposed email addresses for phishing or spam campaigns. The vulnerability also reveals submission patterns, which might help attackers target users more effectively. Sites using the plugin's form feature are at risk even if no active attacks are detected.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA due to unauthorized exposure of personal data (email addresses). Organizations may face fines or penalties for failing to protect user data as required by these regulations.

Mitigation Strategies

Immediately update the Otter Blocks plugin to the latest version beyond 3.2.6. If an update is unavailable, consider disabling the plugin or removing the Form block feature. Restrict subscriber-level access to sensitive data and review user roles to ensure least privilege.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102002. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart