The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts
History

Thu, 31 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Pickplugins
Pickplugins post Grid
CPEs cpe:2.3:a:pickplugins:post_grid:*:*:*:*:*:wordpress:*:*
Vendors & Products Pickplugins
Pickplugins post Grid
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 Aug 2024 13:00:00 +0000

Type Values Removed Values Added
Description The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not prevent password protected posts from being displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-04-11T15:36:31.247Z

Updated: 2024-10-31T15:07:40.694Z

Reserved: 2024-01-25T13:00:04.765Z

Link: CVE-2024-0881

cve-icon Vulnrichment

Updated: 2024-08-01T18:18:18.980Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-11T16:15:24.800

Modified: 2024-11-21T08:47:35.643

Link: CVE-2024-0881

cve-icon Redhat

No data.