{ "id": "CVE-2021-24652", "sourceIdentifier": "contact@wpscan.com", "published": "2021-09-27T16:15:08.900", "lastModified": "2021-11-05T21:10:26.983", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "The PostX \u00e2\u20ac\u201c Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values." }, { "lang": "es", "value": "El plugin PostX - Gutenberg Blocks for Post Grid de WordPress versiones anteriores a 2.4.10, lleva a cabo comprobaciones incorrectas antes de permitir a cualquier usuario conectado llevar a cabo algunas peticiones basadas en ajax, permitiendo a cualquier usuario modificar, eliminar o a\u00f1adir valores ultp_options" } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 2.8, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE", "baseScore": 4.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "contact@wpscan.com", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-863" } ] }, { "source": "nvd@nist.gov", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-863" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:wpxpo:postx_-_gutenberg_blocks_for_post_grid:*:*:*:*:*:wordpress:*:*", "versionEndExcluding": "2.4.10", "matchCriteriaId": "E1287874-AD93-449E-8275-E11B370C69AC" } ] } ] } ], "references": [ { "url": "https://wpscan.com/vulnerability/5375bd3e-a30d-4f24-9b17-470b28a8231c", "source": "contact@wpscan.com", "tags": [ "Third Party Advisory" ] } ] }