Description
Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23.
Published: 2025-12-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WordPress Post Grid and Gutenberg Blocks plugin contains an Insecure Direct Object Reference vulnerability that allows an attacker to read content belonging to other users. The flaw arises from improperly controlled access keys and is classified as CWE‑639. The impact includes leakage of private posts or scheduled content, but does not grant code execution or full system compromise.

Affected Systems

All installations of PickPlugins Post Grid and Gutenberg Blocks plugin running versions through 2.3.23 are affected. The vulnerability applies to the WordPress plugin regardless of the site’s overall WordPress version.

Risk and Exploitability

The CVSS score of 5.3 marks it as a moderate severity issue, while the EPSS score of less than 1% indicates a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers likely exploit the IDOR via crafted web requests containing the wrong user identifier, potentially without authentication or with minimal privilege. The most common exploitation path uses an HTTP request with altered parameters to access the owner’s content.

Generated by OpenCVE AI on April 29, 2026 at 18:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PickPlugins Post Grid and Gutenberg Blocks to version 2.3.24 or later.
  • If an upgrade is not immediately possible, disable or remove the plugin from the WordPress installation until a patch is applied.
  • Review and audit all posts to detect any unintended exposure of private or sensitive content due to the IDOR flaw.

Generated by OpenCVE AI on April 29, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.3.19. Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23.
Title WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.19 - Insecure Direct Object References (IDOR) vulnerability WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.23 - Insecure Direct Object References (IDOR) vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Pickplugins
Pickplugins post Grid
Wordpress
Wordpress wordpress
Vendors & Products Pickplugins
Pickplugins post Grid
Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 17:00:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.3.19.
Title WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.19 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Pickplugins Post Grid
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:09.149Z

Reserved: 2025-10-24T14:26:26.918Z

Link: CVE-2025-63043

cve-icon Vulnrichment

Updated: 2025-12-18T18:50:42.628Z

cve-icon NVD

Status : Deferred

Published: 2025-12-18T17:15:55.157

Modified: 2026-04-23T15:35:00.307

Link: CVE-2025-63043

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T18:45:17Z

Weaknesses