Sensitive Information Exposure in Post Grid and Gutenberg Blocks Plugin for WordPress
CVE-2024-13796

5.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
28 February 2025

What is CVE-2024-13796?

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is susceptible to sensitive information exposure due to improper access controls in the /wp-json/post-grid/v2/get_users REST API endpoint. This vulnerability allows unauthenticated attackers to gain access to sensitive user data, including email addresses and other personal information, potentially leading to privacy breaches. Web administrators must take immediate action to secure their sites by updating to the latest version, ensuring that sensitive data is adequately protected.

Affected Version(s)

Post Grid 0 <= 2.3.6

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wesley
.