Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-0717
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-0717 is a Sensitive Information Exposure vulnerability in the LottieFiles – Lottie block for Gutenberg plugin for WordPress, classified under CWE-200. It affects all versions up to and including 3.0.0, allowing unauthenticated attackers to retrieve the site owner's LottieFiles.com API access token and email address via an unprotected REST API endpoint. The vulnerability was reported by Wordfence and published on January 14, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, NVD).

Technical details

The root cause is improper access control on the /wp-json/lottiefiles/v1/settings/ REST API endpoint, which exposes sensitive configuration data without requiring authentication (CWE-200). The vulnerability is only exploitable when the site administrator has enabled the 'Share LottieFiles account with other WordPress users' option, which causes the endpoint to return the account's API access token and email address in its response. Source code analysis of common.php in plugin version 3.0.0 confirms the endpoint lacks authentication checks before returning credential data (Wordfence, WordPress Plugin Trac).

Impact

Successful exploitation allows any unauthenticated attacker to obtain the site owner's LottieFiles.com API access token and associated email address. With the API token, an attacker could access or manipulate the site owner's LottieFiles.com account, potentially altering animation assets served to website visitors or abusing the account for further attacks. The impact is limited to confidentiality (no integrity or availability impact), but credential theft could enable account takeover on the LottieFiles.com platform (Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires no authentication and no user interaction, but is conditional on the 'Share LottieFiles account with other WordPress users' setting being enabled by the site administrator (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the LottieFiles – Lottie block for Gutenberg plugin (version ≤ 3.0.0) using tools like WPScan, Shodan, or by checking /wp-content/plugins/lottiefiles/ for plugin presence.
  2. Check endpoint availability: Send an unauthenticated HTTP GET request to https://<target>/wp-json/lottiefiles/v1/settings/ to determine if the endpoint is accessible and returns data.
  3. Retrieve credentials: If the 'Share LottieFiles account with other WordPress users' option is enabled, the API response will include the site owner's LottieFiles.com API access token and email address in plaintext JSON.
  4. Abuse obtained credentials: Use the harvested API token to authenticate to LottieFiles.com and access or manipulate the account's animation assets, or use the email address for targeted phishing or credential stuffing attacks (Wordfence, WordPress Plugin Trac).

Indicators of compromise

  • Network: Unauthenticated HTTP GET requests to /wp-json/lottiefiles/v1/settings/ in web server access logs, especially from unfamiliar or automated IP addresses.
  • Logs: WordPress access logs showing repeated or scripted requests to the LottieFiles REST API endpoint without session cookies or authentication headers.
  • LottieFiles.com Account: Unexpected logins, API usage, or asset modifications on the associated LottieFiles.com account that do not correspond to legitimate administrator activity.

Mitigation and workarounds

Users should update the LottieFiles – Lottie block for Gutenberg plugin to version 3.0.1 or later, which addresses this vulnerability by restricting access to the sensitive REST API endpoint (WordPress Plugin Trac). As an interim workaround, administrators can disable the 'Share LottieFiles account with other WordPress users' option in the plugin settings, which prevents the endpoint from exposing credentials. Regularly rotating the LottieFiles.com API access token is also recommended if exposure is suspected.

Community reactions

The vulnerability was reported and disclosed by Wordfence, which assigned the CVE and published the advisory on January 14, 2026. Coverage has been picked up by automated vulnerability tracking services including VulDB, Vulners, and CVEFeed, as well as security aggregators such as Infinitsec and Radar Offseq. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database syndication.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-88788MEDIUM6.8
  • text-styler
NoNoSep 19, 2026
CVE-2026-9858MEDIUM4.3
  • wc-partial-shipment
NoYesSep 19, 2026
CVE-2026-9766MEDIUM4.3
  • empik-for-woocommerce
NoYesSep 19, 2026
CVE-2026-9613MEDIUM4.3
  • datalogics
NoYesSep 19, 2026
CVE-2026-87848LOW3.7
  • mpcx-lightbox
NoNoSep 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management