Sensitive Information Exposure in Otter Blocks Plugin for WordPress
CVE-2026-102002

3.1LOW

What is CVE-2026-102002?

The Otter Blocks plugin, utilized for Gutenberg editor and FSE in WordPress, is susceptible to a vulnerability that leads to Sensitive Information Exposure. This flaw permits authenticated users, with subscriber-level permissions and higher, to gain access to sensitive data, including the email addresses of the five most recent form submitters, their submission dates, and the overall count of form submissions. The vulnerability is triggered when the 'otter_form_widget_filter' parameter is utilized, and it becomes active on any standard WordPress site employing the form feature post the normal saving state of the themeisle_blocks_form_emails option.

Affected Version(s)

Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE 0 <= 3.2.6

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman
.