CVE-2024-10728
high-risk
Published 2024-11-16
The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up to, and including, 4.1.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.
Do I need to act?
!
76.1% chance of exploitation in next 30 days
EPSS score — higher than 24% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10
High
NETWORK
/ LOW complexity
Affected Products (1)
Postx
Affected Vendors
References (5)
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/076f36fb-c2fb-43e0-a02...
55
/ 100
high-risk
Severity
30/34 · Critical
Exploitability
20/34 · Moderate
Exposure
5/34 · Minimal