CVE · Medium

CVE-2024-0908 — Advanced Post Block – Display Your Posts Exactly How You Want [advanced-post-block] < 1.13.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-0908 Advanced Post Block – Display Your Posts Exactly How You Want [advanced-post-block] < 1.13.5 Missing Authorization Medium 5.3 < 1.13.5 1.13.5 2024-04-11

CVE-2024-0908

The Advanced Post Block plugin contains a security flaw in its apbPosts() function that is triggered through an AJAX action and lacks proper permission validation in versions up to 1.13.1. This vulnerability allows unauthenticated users to access and retrieve complete post information without authorization, including posts that are protected with passwords. The issue was addressed in version 1.13.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.