Description
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.6 via the 'otter_form_widget_filter' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the email addresses of the five most recent form submitters, their submission dates, and the site's total form submission count. The widget is registered whenever the themeisle_blocks_form_emails option is non-empty — the normal state after any Form block has been saved — meaning the exposure is active on any standard site using the plugin's form feature.
Published: 2026-10-02
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: Sensitive Information Exposure
Action: Patch Now
AI Analysis

Impact

A flaw in the Otter Blocks WordPress plugin allows authenticated users with a Subscriber or higher role to capture the email addresses of the five most recent form submitters, the dates of those submissions and the site’s aggregate form submission count. The vulnerability is triggered by an ‘otter_form_widget_filter’ parameter that is enabled whenever the themeisle_blocks_form_emails option contains data, a condition that occurs after any form block is saved. This weakness is a classic data‑exposure issue driven by the CWE‑200 principle of insufficient information protection.

Affected Systems

The affected product is the Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin from Themeisle. All releases up to and including version 3.2.6 are vulnerable. Sites that have activated the form feature and therefore retained a non‑empty themeisle_blocks_form_emails option will experience the exposure; the issue is not limited to a specific configuration beyond this standard usage.

Risk and Exploitability

The CVSS score of 3.1 signals low severity, and the EPSS score is not available, so the exploitation likelihood is considered modest. Because the payload targets authenticated users, attackers can gain the data by simply logging in with a Subscriber role, which is a level of access many sites grant. The vulnerability does not provide code execution or denial‑of‑service, but it does allow an attacker to harvest user email addresses and potentially use them for social‑engineering or phishing. The feature is listed outside the CISA KEV catalog, indicating no publicly known exploits have been observed at the time of this analysis.

Generated by OpenCVE AI on October 2, 2026 at 08:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Otter Blocks plugin to the latest version, which removes the exposed parameter and restricts data visibility to authorized administrators.
  • If an immediate update is not possible, disable the dashboard form widget or delete the themeisle_blocks_form_emails option so the plugin stops registering the filter that leaks information.
  • Review the site’s user role assignments and remove or downgrade any Subscriber accounts that are not required, limiting the pool of users who could exploit the vulnerability.

Generated by OpenCVE AI on October 2, 2026 at 08:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.6 via the 'otter_form_widget_filter' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the email addresses of the five most recent form submitters, their submission dates, and the site's total form submission count. The widget is registered whenever the themeisle_blocks_form_emails option is non-empty — the normal state after any Form block has been saved — meaning the exposure is active on any standard site using the plugin's form feature.
Title Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T07:39:24.233Z

Reserved: 2026-09-28T16:51:18.173Z

Link: CVE-2026-102002

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:16:59.867

Modified: 2026-10-02T08:16:59.867

Link: CVE-2026-102002

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor