The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up to, and including, 4.1.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpxpo
Wpxpo postx - Gutenberg Blocks For Post Grid |
|
CPEs | cpe:2.3:a:wpxpo:postx_-_gutenberg_blocks_for_post_grid:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpxpo
Wpxpo postx - Gutenberg Blocks For Post Grid |
|
Metrics |
ssvc
|
Sat, 16 Nov 2024 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up to, and including, 4.1.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. | |
Title | PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/Activation | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-16T04:29:15.146Z
Updated: 2024-11-19T16:06:27.550Z
Reserved: 2024-11-02T01:38:53.821Z
Link: CVE-2024-10728
Vulnrichment
Updated: 2024-11-18T21:52:39.691Z
NVD
Status : Awaiting Analysis
Published: 2024-11-16T05:15:12.510
Modified: 2024-11-18T17:11:17.393
Link: CVE-2024-10728
Redhat
No data.