The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an administrator.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Jan 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an administrator. | |
Title | Post Grid and Gutenberg Blocks 2.2.85 - 2.3.3 - Unauthenticated Privilege Escalation | |
Weaknesses | CWE-269 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-01-15T09:25:53.837Z
Updated: 2025-01-15T09:25:53.837Z
Reserved: 2024-10-08T16:30:18.931Z
Link: CVE-2024-9636
Vulnrichment
No data.
NVD
Status : Received
Published: 2025-01-15T10:15:08.607
Modified: 2025-01-15T10:15:08.607
Link: CVE-2024-9636
Redhat
No data.