What is CVE-2026-13153?
The Gutenberg Essential Blocks WordPress plugin before version 6.4.0 fails to restrict access to one of its public REST routes, which over-fetches non-public WooCommerce sales data. This allows unauthenticated attackers to read the lifetime number of units sold for any published product. The plugin should be upgraded to version 6.4.0 or later immediately.
Azərbaycanca: Gutenberg Essential Blocks WordPress plaginində 6.4.0 versiyasından əvvəl müəyyən bir REST route-a giriş məhdudlaşdırılmayıb. Bu zəiflik autentifikasiya olunmamış istifadəçilərə WooCommerce məhsullarının ömürlük satış sayı kimi məxfi metrik məlumatları oxumağa imkan verir. Plagin dərhal 6.4.0 və ya daha yeni versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What data does CVE-2026-13153 expose in the Gutenberg Essential Blocks plugin?
This vulnerability allows unauthenticated attackers to read confidential metric data, such as the lifetime number of units sold for WooCommerce products, via a REST route.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.