What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a through 2.6.11.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a through 2.6.11.
Explanation of Vulnerability in Simple Terms
Otter Blocks PRO versions up to 2.6.11 expose sensitive information to authenticated users. A logged-in user with low privileges can read data they should not have access to. The vulnerability does not allow modification or deletion of data, and does not affect site availability. Update to a version newer than 2.6.11.
What an attacker can do
Read sensitive information accessible only to higher-privilege users.
Potential impact on your site
Authenticated users can view private or restricted content not intended for their role.
Conditions required to exploit
Attacker must be logged in with a low-privilege account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities