CVE · Medium

CVE-2024-13796 — Post Grid [post-grid] < 2.3.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13796 Post Grid [post-grid] < 2.3.7 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 2.3.7 2.3.7 2025-02-27

CVE-2024-13796

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress contains a sensitive information exposure flaw affecting versions 2.3.6 and earlier through the /wp-json/post-grid/v2/get_users REST API endpoint. Unauthenticated users can exploit this vulnerability to retrieve confidential user information such as email addresses and other account details. The vulnerability has been resolved in version 2.3.7.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.