Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-0881

Опубликовано: 11 апр. 2024
Источник: nvd
CVSS3: 5.4
EPSS Средний

Описание

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pickplugins:post_grid:*:*:*:*:*:wordpress:*:*
Версия до 2.2.76 (исключая)

EPSS

Процентиль: 94%
0.13073
Средний

5.4 Medium

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.4
github
почти 2 года назад

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not prevent password protected posts from being displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

EPSS

Процентиль: 94%
0.13073
Средний

5.4 Medium

CVSS3

Дефекты

NVD-CWE-noinfo