Description
WordPress Plugin Post Grid Gutenberg Blocks and WordPress Blog-PostX is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change arbitrary options, which can be used to enable new user registration and set the default role for new users to Administrator. WordPress Plugin Post Grid Gutenberg Blocks and WordPress Blog-PostX version 4.1.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.1.3 or latest
References
Related Vulnerabilities
WordPress Plugin WP Realtime Sitemap Multiple Unspecified Vulnerabilities (1.5.5)
Ruby on Rails Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0276)
WordPress Plugin Social Login Lite For WooCommerce Security Bypass (1.6.0)
WordPress Plugin WP Easy Gallery Cross-Site Scripting (4.1.4)