SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-4945

MEDIUM · CVSS 5.3 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Otter Blocks plugin for WordPress is susceptible to an Insecure Direct Object Reference vulnerability, allowing unauthenticated attackers to exploit the 'watch_checkout' function. By manipulating the product_id parameter in the Stripe checkout URL, attackers can gain access to premium products without proper payment. WordPress site administrators using this plugin should prioritize patching to mitigate potential financial losses and unauthorized access.

CVE
CVE-2026-4945
Severity
MEDIUM
CVSS
5.3
EPSS
0.30%
WordPress

Original NVD Description

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.7 via the 'watch_checkout' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to pay for a lower-cost product while obtaining entitlement for a premium product by manipulating the product_id parameter independently of the price_id parameter in the Stripe checkout URL.