CVE-2024-5326
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'postx_presets_callback' function in all versions up to, and including, 4.1.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.
El complemento The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX de WordPress es vulnerable a modificaciones no autorizadas de datos debido a una falta de verificación de capacidad en la función 'postx_presets_callback' en todas las versiones hasta la 4.1.2 incluida. Esto hace posible que atacantes autenticados, con acceso de nivel de colaborador y superior, cambien opciones arbitrarias en los sitios afectados. Esto se puede utilizar para habilitar el registro de nuevos usuarios y establecer la función predeterminada para los nuevos usuarios en Administrador.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-05-24 CVE Reserved
- 2024-05-29 CVE Published
- 2024-06-01 EPSS Updated
- 2024-06-01 First Exploit
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (6)
URL | Date | SRC |
---|---|---|
https://github.com/truonghuuphuc/CVE-2024-5326-Poc | 2024-06-01 | |
https://github.com/cve-2024/CVE-2024-5326-Poc | 2024-06-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpxpo Search vendor "Wpxpo" | Post Grid Gutenberg Blocks And WordPress Blog Plugin – PostX Search vendor "Wpxpo" for product "Post Grid Gutenberg Blocks And WordPress Blog Plugin – PostX" | <= 4.1.2 Search vendor "Wpxpo" for product "Post Grid Gutenberg Blocks And WordPress Blog Plugin – PostX" and version " <= 4.1.2" | en |
Affected
|