CVE-2024-13798

Severity
5.3MEDIUM
EPSS
0.2%
top 52.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22

Description

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. This is due to insufficient verification on form fields. This makes it possible for unauthenticated attackers to create new orders for products and mark them as paid without actually completing a payment.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5pickplugins/post_grid2.3.5

Patches

🔴Vulnerability Details

2
CVEList
Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation2025-02-22
GHSA
GHSA-c7q7-2vr2-wj3p: The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and includin2025-02-22
CVE-2024-13798 (MEDIUM CVSS 5.3) | The Post Grid and Gutenberg Blocks | cvebase.io