Description
WordPress Plugin Post Grid Gutenberg Blocks and WordPress Blog-PostX is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change arbitrary options, which can be used to enable new user registration and set the default role for new users to Administrator. WordPress Plugin Post Grid Gutenberg Blocks and WordPress Blog-PostX version 4.1.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.1.3 or latest
References
Related Vulnerabilities
Oracle Application Server Other Vulnerability (CVE-2007-0286)
Oracle JRE CVE-2017-10309 Vulnerability (CVE-2017-10309)
Oracle Application Server Other Vulnerability (CVE-2006-5354)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-4791)
WordPress Plugin Knews Multilingual Newsletters 'ff' Parameter Cross-Site Scripting (1.1.0)