LottieFiles Gutenberg Block Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure exists in the LottieFiles – Lottie block for Gutenberg plugin for WordPress, in all versions through 3.0.0. The issue arises via the '/wp-json/lottiefiles/v1/settings/' REST API endpoint, where unauthenticated attackers can access the site owner's LottieFiles.com account credentials. This includes the API access token and email address, but only if the 'Share LottieFiles account with other WordPress users' option is enabled.

Impact

Exploitation of this vulnerability allows unauthenticated attackers to access sensitive information, specifically LottieFiles.com account credentials, including the API access token and email address of the site owner.

Added: Jan 14, 2026, 6:47 AM
Updated: Jan 14, 2026, 6:47 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.1
remediation
0.0
relevance
2.1
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.