CVE · Medium

CVE-2024-7418 — The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid [the-post-grid] < 7.7.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-7418 The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid [the-post-grid] < 7.7.12 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 7.7.12 7.7.12 2024-08-28

CVE-2024-7418

The Post Grid plugin for WordPress contains a flaw in its post_query_guten and post_query functions, which allows authorized users with at least contributor privileges to access non-public post data, such as drafts or future posts. This sensitive information exposure affects all versions of the plugin up to 7.7.11.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.