/Vulnerability Library

LottieFiles for Gutenberg <= 3.0.0 - Unauthenticated Settings Disclosure

CVE-2026-0717
Verified

Description

The LottieFiles – Lottie block for Gutenberg plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.0 via the `/wp-json/lottiefiles/v1/settings/` REST API endpoint. This makes it possible for unauthenticated attackers to retrieve the site owner's LottieFiles.com account credentials including their API access token and email address when the 'Share LottieFiles account with other WordPress users' option is enabled.

Severity

Medium

Exploit Probability

1%

Published Date

August 15, 2026

Template Author

str4k3r

CVE-2026-0717.yaml
5.0Severity

CVSS Metrics

CVE ID:
cve-2026-0717

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/19b159ca-4b41-48b4-880d-9b9dc44b3463?source=cvehttps://plugins.trac.wordpress.org/browser/lottiefiles/tags/3.0.0/src/common.php?marks=21,122#L21https://plugins.trac.wordpress.org/changeset/3442469/

Remediation Steps

Update to the latest version beyond 3.0.0.