First published: Thu Aug 29 2024(Updated: )
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.7.11 via the post_query_guten and post_query functions. This makes it possible for authenticated attackers, with contributor-level access and above, to extract information from posts that are not public (i.e. draft, future, etc..).
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Radiustheme The Post Grid | <7.7.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7418 is classified as a Medium severity vulnerability due to the potential for sensitive information exposure.
To fix CVE-2024-7418, update the The Post Grid plugin to version 7.7.12 or later.
CVE-2024-7418 affects all versions of The Post Grid plugin for WordPress up to and including version 7.7.11.
CVE-2024-7418 can potentially expose sensitive information through the post_query_guten and post_query functions.
The vendor of the affected product is Radiustheme, which develops The Post Grid plugin for WordPress.