Impact
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin contains a missing capability check (CWE‑862) in the ultp_shareCount_callback() function, allowing any attacker to alter the share_count post meta of any post, including private or draft ones. This flaw compromises data integrity and can be used to manipulate engagement metrics.
Affected Systems
WordPress users of the "Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX" plugin, with all versions up to and including 5.0.5, are affected. Updates beyond 5.0.5 are presumed to contain the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity. EPSS information is unavailable and the issue is not listed in the CISA KEV catalog, so the likelihood of exploitation is unknown but potentially significant given the unauthenticated nature of the attack vector. Exploitation would involve sending crafted requests to the plugin’s callback endpoint from an external source, requiring no special privileges.
OpenCVE Enrichment