The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.7.11 via the post_query_guten and post_query functions. This makes it possible for authenticated attackers, with contributor-level access and above, to extract information from posts that are not public (i.e. draft, future, etc..).
References
Configurations
History
No history.
Information
Published : 2024-08-29 11:15
Updated : 2024-10-04 16:01
NVD link : CVE-2024-7418
Mitre link : CVE-2024-7418
CVE.ORG link : CVE-2024-7418
JSON object : View
Products Affected
radiustheme
- the_post_grid
CWE