First published: Thu Apr 11 2024(Updated: )
The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Combo Blocks | <2.2.76 | |
WordPress Post Grid | <2.2.76 | |
WordPress Form Maker | <2.2.76 | |
WordPress Popup Maker | <2.2.76 | |
WooCommerce Blocks | <2.2.76 | |
WordPress Post Blocks | <2.2.76 | |
WordPress Post Carousel | <2.2.76 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0881 is considered to have a medium severity due to improper authorization that exposes password-protected posts.
To fix CVE-2024-0881, update the affected WordPress plugins to version 2.2.76 or later.
CVE-2024-0881 affects the Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, and Post Carousel plugins prior to version 2.2.76.
The impact of CVE-2024-0881 allows unauthorized users to view content from password-protected posts through certain unauthenticated AJAX actions.
No, downgrading will not resolve CVE-2024-0881; it is essential to upgrade to the latest plugin versions to ensure security.