Executive brief
GenerateBlocks, a popular layout and design tool for WordPress websites, contains a security flaw that can expose sensitive information. An attacker with basic user permissions could access data that is normally hidden from public view. This information could potentially be used to facilitate further attacks against the website or its users.
Technical details
The GenerateBlocks plugin for WordPress is vulnerable to the insertion of sensitive information into sent data (CWE-201). This flaw allows an authenticated attacker, typically with 'Contributor' level privileges or higher, to retrieve sensitive data that has been embedded but should not be accessible to their user role. The vulnerability stems from improper handling of sensitive information within the plugin's data output mechanisms. An attacker can exploit this over the network without user interaction to gain unauthorized access to internal site details. The issue is resolved in version 2.1.1.
Affected products
- Tom Usborne (GeneratePress) GenerateBlocks <= 2.1.0
Timeline
- 2025-08-03: other: Reported by researcher Abu Hurayra
- 2026-05-27: advisory: Published by Patchstack and NVD
- 2026-05-27: patched: Patch released in version 2.1.1