Sensitive Information Exposure in Post Grid and Gutenberg Blocks Plugin for WordPress
CVE-2024-13796
7.5HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 28 February 2025
Summary
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is susceptible to sensitive information exposure due to improper access controls in the /wp-json/post-grid/v2/get_users REST API endpoint. This vulnerability allows unauthenticated attackers to gain access to sensitive user data, including email addresses and other personal information, potentially leading to privacy breaches. Web administrators must take immediate action to secure their sites by updating to the latest version, ensuring that sensitive data is adequately protected.
Affected Version(s)
Post Grid and Gutenberg Blocks – ComboBlocks * <= 2.3.6
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
wesley