CVE · High

CVE-2023-7072 — Post Grid [post-grid] < 2.2.69

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-7072 Post Grid [post-grid] < 2.2.69 Exposure of Sensitive Information Through Data Queries High 7.5 < 2.2.69 2.2.69 2024-03-12

CVE-2023-7072

The Post Grid Combo plugin through version 2.2.68 contains a sensitive data exposure vulnerability in its 'get_posts' REST API endpoint that can be exploited by unauthenticated users. Attackers can leverage this flaw to access draft posts, password-protected posts, and the passwords associated with those protected posts. The vulnerability affects all versions up to and including 2.2.68, and has been resolved in version 2.2.69 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.