
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0717 is a Sensitive Information Exposure vulnerability in the LottieFiles – Lottie block for Gutenberg plugin for WordPress, classified under CWE-200. It affects all versions up to and including 3.0.0, allowing unauthenticated attackers to retrieve the site owner's LottieFiles.com API access token and email address via an unprotected REST API endpoint. The vulnerability was reported by Wordfence and published on January 14, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, NVD).
The root cause is improper access control on the /wp-json/lottiefiles/v1/settings/ REST API endpoint, which exposes sensitive configuration data without requiring authentication (CWE-200). The vulnerability is only exploitable when the site administrator has enabled the 'Share LottieFiles account with other WordPress users' option, which causes the endpoint to return the account's API access token and email address in its response. Source code analysis of common.php in plugin version 3.0.0 confirms the endpoint lacks authentication checks before returning credential data (Wordfence, WordPress Plugin Trac).
Successful exploitation allows any unauthenticated attacker to obtain the site owner's LottieFiles.com API access token and associated email address. With the API token, an attacker could access or manipulate the site owner's LottieFiles.com account, potentially altering animation assets served to website visitors or abusing the account for further attacks. The impact is limited to confidentiality (no integrity or availability impact), but credential theft could enable account takeover on the LottieFiles.com platform (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires no authentication and no user interaction, but is conditional on the 'Share LottieFiles account with other WordPress users' setting being enabled by the site administrator (Wordfence).
/wp-content/plugins/lottiefiles/ for plugin presence.https://<target>/wp-json/lottiefiles/v1/settings/ to determine if the endpoint is accessible and returns data./wp-json/lottiefiles/v1/settings/ in web server access logs, especially from unfamiliar or automated IP addresses.Users should update the LottieFiles – Lottie block for Gutenberg plugin to version 3.0.1 or later, which addresses this vulnerability by restricting access to the sensitive REST API endpoint (WordPress Plugin Trac). As an interim workaround, administrators can disable the 'Share LottieFiles account with other WordPress users' option in the plugin settings, which prevents the endpoint from exposing credentials. Regularly rotating the LottieFiles.com API access token is also recommended if exposure is suspected.
The vulnerability was reported and disclosed by Wordfence, which assigned the CVE and published the advisory on January 14, 2026. Coverage has been picked up by automated vulnerability tracking services including VulDB, Vulners, and CVEFeed, as well as security aggregators such as Infinitsec and Radar Offseq. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database syndication.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."