CVE-2021-24652
—CVSS 3.1
6.5 medium
EPSS
<1%p52
Published
()
Modified
Description
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.
- Vendors
- wpxpo
- Products
- postx - gutenberg blocks for post grid
- Ecosystems
- WordPress
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.