CVE-2024-7418

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.7.11 via the post_query_guten and post_query functions. This makes it possible for authenticated attackers, with contributor-level access and above, to extract information from posts that are not public (i.e. draft, future, etc..).
Configurations

Configuration 1 (hide)

cpe:2.3:a:radiustheme:the_post_grid:*:*:*:*:*:wordpress:*:*

History

04 Oct 2024, 16:01

Type Values Removed Values Added
CWE NVD-CWE-noinfo
Summary
  • (es) El complemento The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 7.7.11 incluida a través de las funciones post_query_guten y post_query. Esto permite que atacantes autenticados, con acceso de nivel de colaborador y superior, extraigan información de publicaciones que no son públicas (es decir, borradores, futuras, etc.).
CPE cpe:2.3:a:radiustheme:the_post_grid:*:*:*:*:*:wordpress:*:*
First Time Radiustheme
Radiustheme the Post Grid
References () https://plugins.trac.wordpress.org/changeset/3142599/the-post-grid/trunk/app/Controllers/Blocks/BlockBase.php - () https://plugins.trac.wordpress.org/changeset/3142599/the-post-grid/trunk/app/Controllers/Blocks/BlockBase.php - Patch
References () https://plugins.trac.wordpress.org/changeset/3142599/the-post-grid/trunk/app/Widgets/elementor/rtTPGElementorQuery.php - () https://plugins.trac.wordpress.org/changeset/3142599/the-post-grid/trunk/app/Widgets/elementor/rtTPGElementorQuery.php - Patch
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3142599%40the-post-grid&new=3142599%40the-post-grid&sfp_email=&sfph_mail= - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3142599%40the-post-grid&new=3142599%40the-post-grid&sfp_email=&sfph_mail= - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/dddecb2e-9ad6-4e44-afce-5eba7da6322d?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/dddecb2e-9ad6-4e44-afce-5eba7da6322d?source=cve - Third Party Advisory

29 Aug 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-29 11:15

Updated : 2024-10-04 16:01


NVD link : CVE-2024-7418

Mitre link : CVE-2024-7418

CVE.ORG link : CVE-2024-7418


JSON object : View

Products Affected

radiustheme

  • the_post_grid
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor