Sploitus

CVE-2024-0881

1 known exploit for CVE-2024-0881

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

Pickplugins Post Grid
< 2.2.76
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
16.9% (97th percentile)
NVD status
Analyzed
Published
2024-04-11
CVE-2024-0881 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2024-0881

Proof-of-concept code and exploit modules indexed by Sploitus