PostX - Gutenberg Blocks for Post Grid <= 2.4.9 - Unauthorized Access Controls
2021-08-17 00:00
apple502jStrategic Overview
StatusPatched in 2.4.10
Affected PluginPost Grid Gutenberg Blocks – PostX
Affected Version
< 2.4.10CVSS6.5Medium
CVE
CVE-2021-24652Vulnerability Overview
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.
Technical Analysis
REMEDIATION: Update to version 2.4.10, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C