PT-2024-15886 · WordPress · Vg Postcarousel+5
Krzysztof Zając
·
Published
2024-04-11
·
Updated
2025-05-09
·
CVE-2024-0881
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin versions prior to 2.2.76
Description
The issue concerns improper authorization in the WordPress plugin, allowing unauthenticated users to read password-protected posts through certain unauthenticated AJAX actions. This results in unauthorized access to sensitive information.
Recommendations
For versions prior to 2.2.76, update to version 2.2.76 or later to resolve the issue. As a temporary workaround, consider restricting access to password-protected posts or disabling the affected AJAX actions until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Form Maker
Popup Maker
Post Blocks
Vg Postcarousel
The Post Grid
Woocommerce Blocks