Description
WordPress Plugin Post Grid Gutenberg Blocks and WordPress Blog-PostX is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change arbitrary options, which can be used to enable new user registration and set the default role for new users to Administrator. WordPress Plugin Post Grid Gutenberg Blocks and WordPress Blog-PostX version 4.1.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.1.3 or latest
References
Related Vulnerabilities
Sqlite NULL Pointer Dereference Vulnerability (CVE-2020-9327)
Magento Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2019-7925)
WordPress Plugin WP Background Takeover Directory Traversal (4.1.4)
TCExam Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2021-20113)