CVE-2026-102002: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in themeisle Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.6 via the 'otter_form_widget_filter' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the email addresses of the five most recent form submitters, their submission dates, and the site's total form submission count. The widget is registered whenever the themeisle_blocks_form_emails option is non-empty — the normal state after any Form block has been saved — meaning the exposure is active on any standard site using the plugin's form feature.
AI Analysis
Technical Summary
CVE-2026-102002 describes a sensitive information exposure vulnerability (CWE-200) in the Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE WordPress plugin. Versions up to and including 3.2.6 are affected. Authenticated users with subscriber-level privileges can exploit the 'otter_form_widget_filter' parameter to extract email addresses of recent form submitters, submission dates, and the total count of form submissions. The vulnerability is active on any site using the plugin's form feature where the themeisle_blocks_form_emails option is non-empty.
Potential Impact
The vulnerability allows low-privileged authenticated users to access sensitive user information (email addresses and submission metadata) that should not be exposed. This could lead to privacy violations and potential targeted phishing or spam attacks. The CVSS score is low (3.1) reflecting limited impact and the requirement for authenticated access.
Mitigation Recommendations
No official patch or fix is currently documented. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict subscriber-level access where possible and monitor plugin updates from themeisle for a security update addressing this issue.
CVE-2026-102002: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in themeisle Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
Description
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.6 via the 'otter_form_widget_filter' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the email addresses of the five most recent form submitters, their submission dates, and the site's total form submission count. The widget is registered whenever the themeisle_blocks_form_emails option is non-empty — the normal state after any Form block has been saved — meaning the exposure is active on any standard site using the plugin's form feature.
CVSS v3.1
Score 3.1low
Affected software
themeisle
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-102002 describes a sensitive information exposure vulnerability (CWE-200) in the Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE WordPress plugin. Versions up to and including 3.2.6 are affected. Authenticated users with subscriber-level privileges can exploit the 'otter_form_widget_filter' parameter to extract email addresses of recent form submitters, submission dates, and the total count of form submissions. The vulnerability is active on any site using the plugin's form feature where the themeisle_blocks_form_emails option is non-empty.
Potential Impact
The vulnerability allows low-privileged authenticated users to access sensitive user information (email addresses and submission metadata) that should not be exposed. This could lead to privacy violations and potential targeted phishing or spam attacks. The CVSS score is low (3.1) reflecting limited impact and the requirement for authenticated access.
Mitigation Recommendations
No official patch or fix is currently documented. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict subscriber-level access where possible and monitor plugin updates from themeisle for a security update addressing this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-09-28T16:51:18.173Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abf6160a43b0b3b898ac6d5
Added to database: 10/02/2026, 07:46:40 UTC
Last enriched: 10/02/2026, 08:02:54 UTC
Last updated: 10/03/2026, 03:45:56 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.