WP Clinic
Log in Sign up

CVE · Medium

CVE-2024-13796 — Post Grid [post-grid] < 2.3.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13796 Post Grid [post-grid] < 2.3.7 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 2.3.7 2.3.7 2025-02-27

CVE-2024-13796

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.6 via the /wp-json/post-grid/v2/get_users REST API This makes it possible for unauthenticated attackers to extract sensitive data including including emails and other user data.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.