CVE-2026-13153 PUBLISHED

Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint

Assigner: WPScan
Reserved: 24.06.2026 Published: 06.08.2026 Updated: 06.08.2026

The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.

Product Status

Vendor Unknown
Product Gutenberg Essential Blocks
Versions Default: unaffected
  • affected from 0 to 6.4.0 (excl.)

Credits

  • Revanth Hari Narayana Matte finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE