Sensitive Information Exposure in Post Grid and Gutenberg Blocks Plugin for WordPress
CVE-2024-13796

7.5HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
28 February 2025

Summary

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is susceptible to sensitive information exposure due to improper access controls in the /wp-json/post-grid/v2/get_users REST API endpoint. This vulnerability allows unauthenticated attackers to gain access to sensitive user data, including email addresses and other personal information, potentially leading to privacy breaches. Web administrators must take immediate action to secure their sites by updating to the latest version, ensuring that sensitive data is adequately protected.

Affected Version(s)

Post Grid and Gutenberg Blocks – ComboBlocks * <= 2.3.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wesley
.