CVE-2026-13153: Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Gutenberg Essential Blocksto a version that resolves this vulnerability.Fixed in 6.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13153?
The severity rating of CVE-2026-13153 is 28, indicating a moderate risk due to potential information leakage.
How do I fix CVE-2026-13153?
To fix CVE-2026-13153, update the Gutenberg Essential Blocks WordPress plugin to version 6.4.0 or later.
What type of vulnerability is represented by CVE-2026-13153?
CVE-2026-13153 is classified as an information leakage vulnerability that allows unauthorized access to WooCommerce sales data.
What impact does CVE-2026-13153 have on my site?
CVE-2026-13153 may expose lifetime sales data for your WooCommerce products to unauthenticated users, posing a risk to your business's confidential metrics.
Who is affected by CVE-2026-13153?
CVE-2026-13153 affects users of the Gutenberg Essential Blocks plugin for WordPress versions prior to 6.4.0.