CVE-2021-24661: PostX Gutenberg Blocks Saved Templates Addon < 2.4.10 - Private Content Disclosure
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID.
Other sources
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24661?
CVE-2021-24661 is a vulnerability in the PostX - Gutenberg Blocks for Post Grid WordPress plugin, allowing unauthorized access to password-protected or private posts for users with Contributor roles or higher.
How severe is CVE-2021-24661?
CVE-2021-24661 has a severity rating of medium with a CVSS score of 4.3.
What software versions are affected by CVE-2021-24661?
The PostX - Gutenberg Blocks for Post Grid WordPress plugin before version 2.4.10 is affected by CVE-2021-24661.
What is the Common Weakness Enumeration (CWE) for CVE-2021-24661?
CVE-2021-24661 is associated with CWE-200, which is the classification for Information Exposure.
How can I fix CVE-2021-24661?
To fix CVE-2021-24661, update the PostX - Gutenberg Blocks for Post Grid WordPress plugin to version 2.4.10 or higher.