PoC Index

CVE-2024-0881

MEDIUM 5.4EPSS 16.9%

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS
16.91% chance of exploitation in the next 30 days, 97th percentile
Nuclei
medium · CWE-284
Published
2024-04-11
Updated
2024-10-31

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related