CVE-2025-66058: WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.17 - Broken Access Control vulnerability
Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.3.17.
Other sources
Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.17.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66058?
CVE-2025-66058 is classified as a high severity vulnerability due to its impact on access control.
How do I fix CVE-2025-66058?
To fix CVE-2025-66058, update the Post Grid and Gutenberg Blocks plugin to the latest version beyond 2.3.17.
What software is affected by CVE-2025-66058?
CVE-2025-66058 affects Post Grid and Gutenberg Blocks versions up to 2.3.17.
What type of vulnerability is CVE-2025-66058?
CVE-2025-66058 is a missing authorization vulnerability that allows exploitation due to incorrectly configured access control.
Can CVE-2025-66058 lead to data exposure?
Yes, if exploited, CVE-2025-66058 can lead to unauthorized access to sensitive data.