CVE · High

CVE-2026-2892 — Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.1.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-2892 Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE [otter-blocks] < 3.1.5 Improper Authorization High 7.5 < 3.1.5 3.1.5 2026-04-29

CVE-2026-2892

An exploitable flaw has been identified in the Otter Blocks plugin for WordPress, impacting all versions up to and including 3.1.4. The issue arises from the 'get_customer_data' method's reliance on an unvalidated cookie named 'o_stripe_data', which contains information about Stripe product ownership. This unchecked data is subsequently trusted by the 'check_purchase' method in one-time payment mode, allowing malicious users to fabricate a valid product ID and access restricted content.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.