Sensitive Information Exposure in Post Grid and Gutenberg Blocks Plugin for WordPress
CVE-2024-13796
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 February 2025
What is CVE-2024-13796?
The Post Grid and Gutenberg Blocks β ComboBlocks plugin for WordPress is susceptible to sensitive information exposure due to improper access controls in the /wp-json/post-grid/v2/get_users REST API endpoint. This vulnerability allows unauthenticated attackers to gain access to sensitive user data, including email addresses and other personal information, potentially leading to privacy breaches. Web administrators must take immediate action to secure their sites by updating to the latest version, ensuring that sensitive data is adequately protected.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Post Grid and Gutenberg Blocks β ComboBlocks * <= 2.3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved