← Back to browse · API

CVE-2024-10728

Severity
HIGH
CVSS
8.8
EPSS
0.36493
Risk score
47.97
CISA KEV
No
PoC
No
Published
2024-11-16
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2024-33453, GHSA-H7J2-R3QV-9Q3V
Products
wpxpo:Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX 0 ≤4.1.16
Sources
euvd EUVD-2024-33453

Description

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up to, and including, 4.1.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

References