PatchSiren cyber security CVE debrief
CVE-2026-13153 Gutenberg Essential Blocks CVE debrief
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product. This issue is rated HIGH with a CVSS score of 7.5. Affected product deployments should be reviewed for exposure and updated to version 6.4.0 or later. The CVE record was published on 2026-08-06T07:16:27.100Z and has not been modified since then. Evidence is based on limited source detail; further verification is recommended.
- Vendor
- Gutenberg Essential Blocks
- Product
- Gutenberg Essential Blocks
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
Administrators of WordPress sites using the Gutenberg Essential Blocks plugin should review and update the plugin to version 6.4.0 or later to prevent potential exploitation. This update is crucial for sites that rely on WooCommerce for sales data, as the exposure of lifetime sales metrics could have significant business implications. Security teams and vulnerability management teams should also be aware of this issue and prioritize updates accordingly. Additionally, operators of affected platforms should verify the exposure of their deployments and take necessary mitigations to protect sensitive sales data. This issue may also be of interest to security researchers and threat intelligence teams monitoring for potential exploits in the wild. Review of compensating controls and monitoring for exposed assets is also recommended while remediation is scheduled and verified. Asset inventory and source tracking may also be useful in verifying the exposure of affected deployments. Rollback change windows should be considered if immediate remediation is not feasible. Monitoring and detection logs should be reviewed for exposed assets that need extra review. Exceptions should be tracked and remediated assets should be retested before closing the item, with evidence documented. This issue should be reviewed in the context of existing security policies and procedures for vulnerability management and incident response. The CVSS score of 7.5 indicates a high severity vulnerability that requires immediate attention. The vulnerability management team should prioritize this issue and ensure that affected systems are updated or mitigated as soon as possible. The security team should also review the current security posture and adjust as necessary to prevent similar issues in the future. The affected vendor should also be notified and their guidance followed for remediation. Compensating controls such as web application firewalls or access controls may be necessary for systems that cannot be updated immediately. The issue should also be reviewed in the context of existing compliance and regulatory requirements to ensure that necessary actions are taken to maintain compliance. The
Technical summary
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product. This vulnerability allows for potential exposure of sensitive sales data. Administrators of WordPress sites using the Gutenberg Essential Blocks plugin should review and update the plugin to version 6.4.0 or later to prevent potential exploitation.
Defensive priority
CVE-2026-13153 is rated HIGH with a CVSS score of 7.5. Consider immediate defensive review.
Recommended defensive actions
- Review and update the Gutenberg Essential Blocks WordPress plugin to version 6.4.0 or later.
- Restrict access to public REST routes.
- Verify and limit the exposure of WooCommerce per-product sales metrics.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response. This allows unauthenticated users to read the lifetime number of units sold for any published product. Evidence is based on limited source detail; further verification is recommended.
Official resources
-
CVE-2026-13153 CVE record
CVE.org
-
CVE-2026-13153 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T07:16:27.100Z and has not been modified since then.