CVE-2024-7418: The Post Grid <= 7.7.11 - Authenticated (Contributor+) Information Disclosure
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.7.11 via the postqueryguten and postquery functions. This makes it possible for authenticated attackers, with contributor-level access and above, to extract information from posts that are not public (i.e. draft, future, etc..).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7418?
CVE-2024-7418 is classified as a Medium severity vulnerability due to the potential for sensitive information exposure.
How do I fix CVE-2024-7418?
To fix CVE-2024-7418, update the The Post Grid plugin to version 7.7.12 or later.
Which versions are affected by CVE-2024-7418?
CVE-2024-7418 affects all versions of The Post Grid plugin for WordPress up to and including version 7.7.11.
What kind of sensitive information is exposed in CVE-2024-7418?
CVE-2024-7418 can potentially expose sensitive information through the post_query_guten and post_query functions.
Who is the vendor of the product affected by CVE-2024-7418?
The vendor of the affected product is Radiustheme, which develops The Post Grid plugin for WordPress.