CVE-2025-63043: WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.23 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.3.19.
Other sources
Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63043?
CVE-2025-63043 has a high severity due to the potential for unauthorized access through incorrectly configured access controls.
How do I fix CVE-2025-63043?
To fix CVE-2025-63043, update the PickPlugins Post Grid and Gutenberg Blocks plugin to a version later than 2.3.19.
What versions are affected by CVE-2025-63043?
CVE-2025-63043 affects all versions of Post Grid and Gutenberg Blocks from n/a up to and including 2.3.19.
What kind of vulnerability is CVE-2025-63043?
CVE-2025-63043 is an Authorization Bypass Through User-Controlled Key vulnerability.
Can CVE-2025-63043 lead to data breaches?
Yes, CVE-2025-63043 can lead to data breaches by allowing unauthorized users to access restricted content.