Description
Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive Data.

This issue affects GenerateBlocks: from n/a through 2.1.0.
Published: 2026-05-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability permits an attacker to read sensitive information embedded within the data sent by the GenerateBlocks plugin. The exposed data can include credentials, configuration details, or other confidential content, leaking it to unauthorized parties. The weakness is a classic input handling flaw identified as CWE‑201, where sensitive data is inadvertently included in outputs. The impact is primarily a breach of confidentiality, as attackers could compromise personal or corporate secrets without needing further exploitation.

Affected Systems

The vulnerability affects the WordPress GenerateBlocks plugin provided by Tom:GenerateBlocks. All plugin releases from the earliest version up through 2.1.0 are vulnerable. Users running any version of the plugin compatible with WordPress up to and including 2.1.0 need to address the issue.

Risk and Exploitability

The CVSS score for this flaw is 6.5, indicating moderate severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. An attacker can likely exploit the problem remotely by delivering a request to a WordPress site that uses the plugin, as the data is transmitted over the network. Because the vulnerability involves data exposure rather than code execution or denial of service, the attack vector does not require local compromise; it can be performed from an external network if the site is publicly accessible. The lack of public exploitation data suggests that the threat remains theoretical, but the moderate CVSS and the sensitivity of the exposed data warrant prompt remediation.

Generated by OpenCVE AI on May 27, 2026 at 10:36 UTC.

Remediation

Vendor Solution

Update the WordPress GenerateBlocks plugin to the latest available version (at least 2.1.1).


OpenCVE Recommended Actions

  • Update the GenerateBlocks plugin to version 2.1.1 or later.
  • If an update cannot be applied immediately, disable the GenerateBlocks plugin to prevent sensitive data from being exposed.
  • Review any content that may contain sensitive data processed by the plugin and remove or sanitize it to eliminate the exposure risk.

Generated by OpenCVE AI on May 27, 2026 at 10:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 09:00:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive Data. This issue affects GenerateBlocks: from n/a through 2.1.0.
Title WordPress GenerateBlocks plugin <= 2.1.0 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-27T10:26:56.731Z

Reserved: 2026-05-25T22:10:13.824Z

Link: CVE-2026-48877

cve-icon Vulnrichment

Updated: 2026-05-27T10:26:51.969Z

cve-icon NVD

Status : Deferred

Published: 2026-05-27T09:16:31.977

Modified: 2026-05-27T14:50:47.627

Link: CVE-2026-48877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T10:45:32Z

Weaknesses