The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in… (CVE-2026-102002)
The Otter Blocks plugin for WordPress, up to and including version 3.2.6, contains a vulnerability that allows authenticated users with subscriber-level access or higher to access sensitive information. Specifically, attackers can retrieve email addresses of the five most recent form submitters, their submission dates, and the total form submission count via the 'otter_form_widget_filter' parameter. This exposure occurs when the form emails option is set, which is typical after saving any Form block, making the vulnerability active on standard sites using the plugin's form feature.
AI Analysis
Technical Summary
CVE-2026-102002 describes a sensitive information exposure vulnerability in The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress. The flaw exists in all versions up to and including 3.2.6 and is exploitable through the 'otter_form_widget_filter' parameter. Authenticated users with subscriber-level privileges or higher can extract email addresses of recent form submitters, submission timestamps, and the site's total form submission count. The vulnerability is active on sites using the plugin's form feature, as the widget is registered when the 'themeisle_blocks_form_emails' option is non-empty.
Potential Impact
The vulnerability allows low-privileged authenticated users to access sensitive personal information (email addresses and submission dates) of recent form submitters, potentially violating user privacy. The total form submission count is also disclosed. The CVSS score is 3.1 (low severity), reflecting limited impact and the requirement for authenticated access with high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict subscriber-level user access where possible and monitor plugin updates for a security patch addressing this issue.
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in… (CVE-2026-102002)
Description
The Otter Blocks plugin for WordPress, up to and including version 3.2.6, contains a vulnerability that allows authenticated users with subscriber-level access or higher to access sensitive information. Specifically, attackers can retrieve email addresses of the five most recent form submitters, their submission dates, and the total form submission count via the 'otter_form_widget_filter' parameter. This exposure occurs when the form emails option is set, which is typical after saving any Form block, making the vulnerability active on standard sites using the plugin's form feature.
CVSS v3.1
Score 3.1low
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-102002 describes a sensitive information exposure vulnerability in The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress. The flaw exists in all versions up to and including 3.2.6 and is exploitable through the 'otter_form_widget_filter' parameter. Authenticated users with subscriber-level privileges or higher can extract email addresses of recent form submitters, submission timestamps, and the site's total form submission count. The vulnerability is active on sites using the plugin's form feature, as the widget is registered when the 'themeisle_blocks_form_emails' option is non-empty.
Potential Impact
The vulnerability allows low-privileged authenticated users to access sensitive personal information (email addresses and submission dates) of recent form submitters, potentially violating user privacy. The total form submission count is also disclosed. The CVSS score is 3.1 (low severity), reflecting limited impact and the requirement for authenticated access with high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict subscriber-level user access where possible and monitor plugin updates for a security patch addressing this issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-374g-wg28-cf5f
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-102002"]
- Database Specific Severity
- LOW
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abfeeb9a43b0b3b89e563d8
Added to database: 10/02/2026, 17:49:45 UTC
Last enriched: 10/02/2026, 18:22:13 UTC
Last updated: 10/03/2026, 04:45:56 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.