PostX - Gutenberg Blocks for Post Grid <= 2.4.9 - Unauthorized Access Controls

2021-08-17 00:00
apple502j

Strategic Overview

Status
Patched in 2.4.10
Affected Version< 2.4.10
CVSS6.5Medium
CVECVE-2021-24652
View all Post Grid Gutenberg Blocks – PostX vulnerabilities

Vulnerability Overview

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.

Technical Analysis

REMEDIATION: Update to version 2.4.10, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C