CVE-2024-0881: Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access
The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0881?
CVE-2024-0881 is considered to have a medium severity due to improper authorization that exposes password-protected posts.
How do I fix CVE-2024-0881?
To fix CVE-2024-0881, update the affected WordPress plugins to version 2.2.76 or later.
Which WordPress plugins are affected by CVE-2024-0881?
CVE-2024-0881 affects the Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, and Post Carousel plugins prior to version 2.2.76.
What is the impact of CVE-2024-0881?
The impact of CVE-2024-0881 allows unauthorized users to view content from password-protected posts through certain unauthenticated AJAX actions.
Can I downgrade my plugins to resolve CVE-2024-0881?
No, downgrading will not resolve CVE-2024-0881; it is essential to upgrade to the latest plugin versions to ensure security.