CVE-2024-11080
largeUnauthenticated Hook Injection in WordPress ComboBlocks (Post Grid) Plugin
CVE-2024-11080 is an unauthenticated hook injection flaw (CWE-94) in the Post Grid and Gutenberg Blocks - ComboBlocks WordPress plugin, affecting versions 2.2.32 through 2.3.1. The vulnerable functions in the includes/blocks/form-wrap/function.php file can be reached over the network without authentication, allowing an attacker to invoke WordPress hook functions with arbitrary hooks, provided no other security controls are present in the function. Successful abuse lets the attacker trigger actions registered for those hooks, with impact ranging from content or data manipulation to code execution or privilege changes depending on which hooks and handlers a given site exposes; the 9.8 CVSS score reflects high confidentiality, integrity, and availability impact potential. Any WordPress site running the plugin in versions 2.2.32 through 2.3.1 is affected. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only about a 0.4% chance of exploitation in the next 30 days, so no in-the-wild exploitation is currently known.
What to do: Update the ComboBlocks plugin to the latest available release (any version above 2.3.1) and confirm the installed version on the WordPress Plugins page. Until updating, consider blocking unauthenticated requests to the plugin's form-related endpoints via WAF rules and review the site for unexpected content changes, new users, or modified settings. Since impact depends on which hooks are exposed on each site, check installed plugins/themes for handlers reachable by unauthenticated callers.
| ComboBlocks (WordPress plugin) Post Grid and Gutenberg Blocks - ComboBlocks | 2.2.32 through 2.3.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress, granted no other security controls are present in the function.
- Ecosystems
- WordPress
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.