Record summary

CVE-2023-40211 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 14, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Post Grid Combo – 36+ Gutenberg Blocks

Browse PickPlugins / Post Grid Combo – 36+ Gutenberg Blockspost-grid

Default status: unaffected

CVE ListThrough 2.2.50affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHPost Grid <= 2.2.50 - Information Exposure via REST APICVSS 7.5

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.

Impact

Unauthorized actors can access sensitive information, leading to privacy breaches and potential misuse of data.

Remediation

Update to the latest version beyond 2.2.50 or apply available security patches.

WeaknessesCWE-200
Authorsdaffainfo
Template tagscvecve2023wpwordpresswp-pluginpickpluginspost-gridvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:pickplugins:post_grid_combo:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/post-grid-combo/"

Source: ProjectDiscovery

References

2