CVE-2026-13153

CVE-2026-13153: Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint

Vendor Unknown
Product Gutenberg Essential Blocks
Published August 6, 2026
Last update August 6, 2026

CVSS base score

What the vulnerability does

01Description

The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.

Key dates

02Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated