CVE-2026-48877: WordPress GenerateBlocks plugin <= 2.1.0 - Sensitive Data Exposure vulnerability
Published May 27, 2026
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive Data.
This issue affects GenerateBlocks: from n/a through 2.1.0.
Affected Software
1 affected component
GenerateBlocks GenerateBlocks<=2.1.0
Remediation
Information
Update the WordPress GenerateBlocks plugin to the latest available version (at least 2.1.1).
Event History
May 27, 2026
CVE Published
via MITRE·08:47 AM
Data Sourced
via MITRE·08:47 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-48877?
The severity of CVE-2026-48877 is rated as medium with a score of 6.5.
2
How do I fix CVE-2026-48877?
To fix CVE-2026-48877, update the WordPress GenerateBlocks plugin to at least version 2.1.1.
3
What type of vulnerability is CVE-2026-48877?
CVE-2026-48877 is a Sensitive Data Exposure vulnerability affecting the GenerateBlocks plugin.
4
Which versions of GenerateBlocks are affected by CVE-2026-48877?
CVE-2026-48877 affects GenerateBlocks versions from n/a through 2.1.0.
5
What can attackers do with CVE-2026-48877?
Attackers exploiting CVE-2026-48877 can retrieve embedded sensitive data due to its vulnerability.