Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102002— Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget

Quick assessment

Affected
themeisle Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件 Otter Blocks(Gutenberg 区块、Gutenberg 编辑器及 FSE 的页面构建器)在所有 3.2.6 及以下版本中存在敏感信息泄露漏洞,该漏洞通过 'otter_form_widget_filter' 参数触发。这使得具备订阅者级别或以上权限的已认证攻击者能够提取最近五次表单提交者的电子邮件地址、提交日期以及站点表单提交的总数。只要主题选项 'themeisle_blocks_form_emails' 非空(在保存任意 Form 区块后的正常状态下即满足此条件),该小

CVSS 3.1 · Low

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102002

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget
Source: CVE Program / CVE List V5
Vulnerability Description
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.6 via the 'otter_form_widget_filter' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the email addresses of the five most recent form submitters, their submission dates, and the site's total form submission count. The widget is registered whenever the themeisle_blocks_form_emails option is non-empty — the normal state after any Form block has been saved — meaning the exposure is active on any standard site using the plugin's form feature.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
themeisle Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE 0 ~ 3.2.6 -

II. Public POCs for CVE-2026-102002

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102002

请登录查看更多情报信息。

Other References for CVE-2026-102002 (6)

IV. Related Vulnerabilities

V. Comments for CVE-2026-102002

No comments yet


Leave a comment