PT-2024-18057 · WordPress · Generateblocks

Craig Smith

+1

·

Published

2024-03-13

·

Updated

2025-03-12

·

CVE-2024-1452

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GenerateBlocks plugin for WordPress versions up to, and including, 1.8.2
Description The issue allows authenticated attackers with contributor access and above to expose sensitive information. This includes the ability to see contents of posts and pages in draft or private status, as well as those with scheduled publication dates, via the Query Loop.
Recommendations For GenerateBlocks plugin for WordPress versions up to, and including, 1.8.2, update to a version later than 1.8.2 to resolve the issue. As a temporary workaround, consider restricting access to the Query Loop feature to minimize the risk of exploitation.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-1452

Affected Products

Generateblocks