Sceawere

Vulnerability Detail

CVE-2026-102002UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Otter Blocks Information Exposure Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
15h ago
Vendor
themeisle
Product
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
Attack Type
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.6 via the 'otter_form_widget_filter' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the email addresses of the five most recent form submitters, their submission dates, and the site's total form submission count. The widget is registered whenever the themeisle_blocks_form_emails option is non-empty — the normal state after any Form block has been saved — meaning the exposure is active on any standard site using the plugin's form feature.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-10-02T08:16:59.867Z",
  "pubdate": "2026-10-02T08:16:59.867Z",
  "executiveSummary": "The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress contains a Sensitive Information Exposure vulnerability. This security flaw exists in versions up to and including 3.2.6. The issue allows authenticated users with subscriber-level access or higher to retrieve sensitive metadata related to form submissions.\nThe vulnerability originates from the improper handling of the 'otter_form_widget_filter' parameter. Successful exploitation permits an attacker to exfiltrate the email addresses of the five most recent form submitters, associated submission timestamps, and the aggregate count of all form submissions stored by the plugin.\nThis exposure is active by default on any site that has utilized the plugin's Form block, as the underlying option 'themeisle_blocks_form_emails' is automatically populated upon saving form data. Given that WordPress sites often allow registration of subscriber accounts, this vulnerability presents a significant risk to user privacy and data security. An attacker does not require elevated privileges beyond the default subscriber role to trigger the exposure, making this a highly accessible attack vector for extracting internal site metrics and PII (Personally Identifiable Information).",
  "technicalDetails": "The vulnerability is localized within the 'otter_form_widget_filter' parameter, which handles data retrieval for the plugin's form widget functionality. The root cause lies in an insecure implementation of data access controls that fails to verify the requesting user's authorization level before returning sensitive form submission metadata.\nThe component is registered within the plugin whenever the 'themeisle_blocks_form_emails' option contains data. Because this option is automatically populated upon the successful configuration and saving of any Form block within the Gutenberg editor, the vulnerability is inherently present in most deployments. The plugin fails to enforce proper capability checks (e.g., using 'current_user_can()') when processing the 'otter_form_widget_filter' parameter.\nExploitation follows a predictable path: 1. The attacker authenticates to the WordPress instance using a valid subscriber-level account. 2. The attacker crafts a request targeting the vulnerable parameter. 3. Upon triggering the filter, the plugin executes backend logic that queries the 'themeisle_blocks_form_emails' option. 4. Due to the lack of restrictive access control, the application serializes and returns the sensitive data—specifically the email addresses of the five most recent submitters, the submission dates, and the total submission count—directly to the attacker. 5. The attacker parses this response, successfully exfiltrating PII and telemetry data.\nThe impact of this vulnerability is significant in the context of GDPR and other data privacy regulations. Because the plugin exposes email addresses of site visitors without requiring administrative privileges, it allows for unauthorized data mining and the potential mapping of user activity on the platform. The vulnerability is present in all versions up to and including 3.2.6. The attack occurs over the network via standard HTTP/HTTPS requests that interact with the WordPress REST API or internal AJAX handlers where the filter is registered. Post-exploitation, the attacker gains access to PII which may be leveraged for secondary attacks, such as spear-phishing or social engineering campaigns targeted at the submitters whose data was exposed."
}
CVE-2026-102002: Otter Blocks Information Exposure Vulnerability (LOW Severity, CVSS: 3.1) | Sceawere