VulnerabilityModified
CVE-2021-24652
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.
MEDIUM 6.5EPSS 0.72%
Does this matter?
Lower severity and a low EPSS score (0.72%). Track it; it rarely justifies an emergency change on its own.
Description
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.72% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- wpxpo/postx - gutenberg blocks for post grid
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/5375bd3e-a30d-4f24-9b17-470b28a8231cThird Party Advisory
- https://wpscan.com/vulnerability/5375bd3e-a30d-4f24-9b17-470b28a8231cThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.