The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 via the 'get_posts' REST API Endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including full draft posts and password protected posts, as well as the password for password-protected posts.
History

Wed, 22 Jan 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Pickplugins
Pickplugins post Grid Combo
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:pickplugins:post_grid_combo:*:*:*:*:*:wordpress:*:*
Vendors & Products Pickplugins
Pickplugins post Grid Combo

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-28T15:05:17.990Z

Reserved: 2023-12-21T22:09:26.886Z

Link: CVE-2023-7072

cve-icon Vulnrichment

Updated: 2024-08-02T08:50:08.113Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-12T23:15:46.267

Modified: 2025-01-22T17:40:31.817

Link: CVE-2023-7072

cve-icon Redhat

No data.