CVE-2024-5326
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX (<= 4.1.2)
Vulnerability: Missing Authorization for Arbitrary Options Update
Description:
The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX for WordPress has a vulnerability due to a missing capability check in the postx_presets_callback function. This affects all versions up to and including 4.1.2. As a result, authenticated users with Contributor-level access or higher can modify arbitrary settings on the site.
This vulnerability could allow attackers to enable new user registrations and set the default role for new users to Administrator, potentially giving them full control over the site.

Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX (<= 4.1.2)
Vulnerability: Missing Authorization for Arbitrary Options Update
Description:
The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX for WordPress has a vulnerability due to a missing capability check in the postx_presets_callback function. This affects all versions up to and including 4.1.2. As a result, authenticated users with Contributor-level access or higher can modify arbitrary settings on the site.
This vulnerability could allow attackers to enable new user registrations and set the default role for new users to Administrator, potentially giving them full control over the site.
