Unauthorized Modification of Data Vulnerability in PostX Plugin for WordPress
CVE-2024-5326

8.8HIGH

Key Information:

Summary

The Post Grid Gutenberg Blocks and PostX plugin for WordPress contains a vulnerability that exposes the site to unauthorized data modifications due to an inadequate capability check on the 'postx_presets_callback' function. This defect affects all versions up to and including 4.1.2. Authenticated attackers with Contributor-level access or higher can exploit this vulnerability to alter arbitrary settings on the affected sites. This capability may lead to unauthorized user registration and potentially promote new users to Administrator roles, significantly compromising site integrity and security.

Affected Version(s)

Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX * <= 4.1.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

1337_Wannabe
.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.