Impact
A flaw in the Otter Blocks WordPress plugin allows authenticated users with a Subscriber or higher role to capture the email addresses of the five most recent form submitters, the dates of those submissions and the site’s aggregate form submission count. The vulnerability is triggered by an ‘otter_form_widget_filter’ parameter that is enabled whenever the themeisle_blocks_form_emails option contains data, a condition that occurs after any form block is saved. This weakness is a classic data‑exposure issue driven by the CWE‑200 principle of insufficient information protection.
Affected Systems
The affected product is the Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin from Themeisle. All releases up to and including version 3.2.6 are vulnerable. Sites that have activated the form feature and therefore retained a non‑empty themeisle_blocks_form_emails option will experience the exposure; the issue is not limited to a specific configuration beyond this standard usage.
Risk and Exploitability
The CVSS score of 3.1 signals low severity, and the EPSS score is not available, so the exploitation likelihood is considered modest. Because the payload targets authenticated users, attackers can gain the data by simply logging in with a Subscriber role, which is a level of access many sites grant. The vulnerability does not provide code execution or denial‑of‑service, but it does allow an attacker to harvest user email addresses and potentially use them for social‑engineering or phishing. The feature is listed outside the CISA KEV catalog, indicating no publicly known exploits have been observed at the time of this analysis.
OpenCVE Enrichment