What the vulnerability does
01Description
Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Post Grid: from n/a through 7.9.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Post Grid: from n/a through 7.9.2.
Explanation of Vulnerability in Simple Terms
The Post Grid plugin for WordPress contains an authorization flaw that allows authenticated users with low privileges to access sensitive information they should not be able to view. An attacker with a basic user account can read data that is restricted to higher-privilege roles. The vulnerability affects versions up to 7.9.2 and requires an active WordPress user account to exploit.
What an attacker can do
Read sensitive data restricted to higher-privilege user roles.
Potential impact on your site
Confidential site data may be exposed to any authenticated user, including subscribers or contributors.
Conditions required to exploit
Attacker must have a valid low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities