ZeroHour

CVE-2021-24652

CVSS 3.1
6.5 medium
EPSS
<1%p52
Published
()
Modified
Description

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.

Vendors
wpxpo
Products
postx - gutenberg blocks for post grid
Ecosystems
WordPress
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.