Unauthorized Modification of Data Vulnerability in PostX Plugin for WordPress
CVE-2024-5326
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 May 2024
What is CVE-2024-5326?
The Post Grid Gutenberg Blocks and PostX plugin for WordPress contains a vulnerability that exposes the site to unauthorized data modifications due to an inadequate capability check on the 'postx_presets_callback' function. This defect affects all versions up to and including 4.1.2. Authenticated attackers with Contributor-level access or higher can exploit this vulnerability to alter arbitrary settings on the affected sites. This capability may lead to unauthorized user registration and potentially promote new users to Administrator roles, significantly compromising site integrity and security.
Affected Version(s)
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites β PostX 0 <= 4.1.2