CVE-2026-62036: WordPress All Bootstrap Blocks plugin <= 1.3.31 - Sensitive Data Exposure vulnerability
Published Oct 9, 2026
·Updated
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in AREOI All Bootstrap Blocks all-bootstrap-blocks allows Retrieve Embedded Sensitive Data.This issue affects All Bootstrap Blocks: from n/a through 1.3.31.
Affected Software
1 affected component
AREOI All Bootstrap Blocks<=1.3.31
Event History
Oct 9, 2026
CVE Published
via MITRE·11:49 AM
Data Sourced
via MITRE·11:49 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires low privileges, and does not require user interaction. An attacker would need an account or other low-level authenticated access.
2
What is the impact of successful exploitation?
Successful exploitation can expose embedded sensitive system information. The listed impact is limited to confidentiality; integrity and availability are not affected.
3
Which versions are affected?
All Bootstrap Blocks versions through 1.3.31 are affected. The provided data does not identify a fixed version.