Cyber Resilience

CVE-2024-0881

Pickplugins Post Grid ≤ 2.2.76

Public PoC
Published
11 April 2024
Modified
09 May 2025
CVSS Score v3.1 5.4
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS Score 0.17 97th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2024-0881 is a medium-severity an unspecified weakness vulnerability in Pickplugins Post Grid. Its CVSS base score is 5.4 (Medium).

Operationally, ranked in the top 3% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before version 2.2.76 contains an authorization flaw that exposes password-protected posts through unauthenticated AJAX endpoints. The affected component fails to enforce access controls on certain queries, allowing restricted post content to appear in responses that should be limited to authenticated users with the correct password.

Unauthenticated attackers can invoke the vulnerable AJAX actions to retrieve the full content of password-protected posts. This grants them read access to material that should remain hidden, with the CVSS 5.4 rating reflecting network-exploitable confidentiality and integrity impact without requiring user interaction.

Public references from WPScan document the missing authorization checks and identify the fixed release as 2.2.76. The EPSS score has remained flat at 0.1307 with no observed rise after disclosure.

EU & UK References

Vulnerability Data

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated…

more

users to read such posts

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-1988Same product: Pickplugins Post Grid
CVE-2024-13408Same product: Pickplugins Post Grid
CVE-2024-9645Same product: Pickplugins Post Grid
CVE-2024-13796Same product: Pickplugins Post Grid
CVE-2024-8253Same product: Pickplugins Post Grid
CVE-2024-13798Same vendor: Pickplugins
CVE-2024-13469Same vendor: Pickplugins
CVE-2024-6346Same vendor: Pickplugins
CVE-2023-7072Same vendor: Pickplugins
CVE-2023-40211Same vendor: Pickplugins

Affected Assets

pickplugins
post grid
≤ 2.2.76

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References