Arbitrary Modification of ultp_options Values in PostX – Gutenberg Blocks for Post Grid WordPress Plugin

Arbitrary Modification of ultp_options Values in PostX – Gutenberg Blocks for Post Grid WordPress Plugin

CVE-2021-24652 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.

Learn more about our Wordpress Pen Testing.