CVE-2024-13796: Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.6 via the /wp-json/post-grid/v2/getusers REST API This makes it possible for unauthenticated attackers to extract sensitive data including including emails and other user data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13796?
CVE-2024-13796 is classified as a sensitive information exposure vulnerability.
How do I fix CVE-2024-13796?
To fix CVE-2024-13796, update the Post Grid and Gutenberg Blocks plugin to version 2.3.7 or later.
Who is affected by CVE-2024-13796?
All users of the Post Grid and Gutenberg Blocks plugin for WordPress up to and including version 2.3.6 are affected by CVE-2024-13796.
What data can be exposed due to CVE-2024-13796?
CVE-2024-13796 allows unauthenticated attackers to extract sensitive user information through the REST API.
Is authentication required to exploit CVE-2024-13796?
No, exploitation of CVE-2024-13796 does not require authentication, making it easier for attackers to exploit.