CVE-2023-40211
WordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data Exposure
Record summary
CVE-2023-40211 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 14, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Post Grid Combo – 36+ Gutenberg BlocksBrowse PickPlugins / Post Grid Combo – 36+ Gutenberg Blockspost-gridDefault status: unaffected | CVE List | Through 2.2.50 | affected |
post_grid_comboBrowse pickplugins / post_grid_combo | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHPost Grid <= 2.2.50 - Information Exposure via REST APICVSS 7.5
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.
Impact
Unauthorized actors can access sensitive information, leading to privacy breaches and potential misuse of data.
Remediation
Update to the latest version beyond 2.2.50 or apply available security patches.
Source: ProjectDiscovery