Impact
A REST endpoint added by the Gutenberg Essential Blocks WordPress plugin fails to enforce authentication checks. This oversight allows anyone on the internet to query the endpoint and receive a response that includes the lifetime sales number for any published WooCommerce product, a metric that is not intended for public disclosure. The vulnerability is purely about exposing sensitive commercial data, and does not allow code execution or modification of site content.
Affected Systems
The flaw affects installations of the Gutenberg Essential Blocks WordPress plugin with a version earlier than 6.4.0. Sites that use WordPress, the plugin, and a WooCommerce store are vulnerable because the REST route is part of the plugin’s WooCommerce integration. No further granularity on affected sub‑versions or configuration settings is provided.
Risk and Exploitability
Attacking this weakness requires only an unauthenticated HTTP request to the vulnerable REST endpoint; no special credentials, network foothold, or privilege escalation is necessary. Although no CVSS or EPSS score is given, the exploitability is straightforward and the data exposed is valuable for business intelligence. The vulnerability is not listed in the CISA KEV catalog, but it remains a high‑risk information disclosure for affected sites.
OpenCVE Enrichment