Description
WordPress Plugin Post Grid Gutenberg Blocks and WordPress Blog-PostX is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change arbitrary options, which can be used to enable new user registration and set the default role for new users to Administrator. WordPress Plugin Post Grid Gutenberg Blocks and WordPress Blog-PostX version 4.1.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.1.3 or latest
References
Related Vulnerabilities
WordPress Plugin Thrive Ultimatum Security Bypass (2.3.9.3)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-9033)
WordPress Plugin FeedWordPress Cross-Site Scripting (2014.0805)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-11113)
Oracle JRE Improper Certificate Validation Vulnerability (CVE-2003-1229)