Unauthorized Modification of Data Vulnerability in PostX Plugin for WordPress
CVE-2024-5326
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 30 May 2024
Summary
The Post Grid Gutenberg Blocks and PostX plugin for WordPress contains a vulnerability that exposes the site to unauthorized data modifications due to an inadequate capability check on the 'postx_presets_callback' function. This defect affects all versions up to and including 4.1.2. Authenticated attackers with Contributor-level access or higher can exploit this vulnerability to alter arbitrary settings on the affected sites. This capability may lead to unauthorized user registration and potentially promote new users to Administrator roles, significantly compromising site integrity and security.
Affected Version(s)
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX * <= 4.1.2
References
EPSS Score
50% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved