Sensitive Data Exposure Vulnerability in AREOI All Bootstrap Blocks Plugin
CVE-2026-62036

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 October 2026

What is CVE-2026-62036?

A vulnerability in the AREOI All Bootstrap Blocks plugin exposes sensitive system information, allowing unauthorized users to retrieve embedded sensitive data. This issue is present in all versions up to 1.3.31, posing significant risks to the security of WordPress installations utilizing this plugin. It is crucial for users to take immediate action to safeguard their environments.

Affected Version(s)

All Bootstrap Blocks 0 <= 1.3.31

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bao - BlueRock | Patchstack Bug Bounty Program
.