CVE-2024-0908

The Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the apbPosts() function hooked via an AJAX action in all versions up to, and including, 1.13.4. This makes it possible for unauthenticated attackers to retrieve all post data, including those that may be password protected.
Configurations

No configuration.

History

08 Apr 2026, 18:19

Type Values Removed Values Added
CWE CWE-862
References
  • () https://plugins.trac.wordpress.org/changeset/3081482/advanced-post-block/trunk/plugin.php?old=3077963&old_path=advanced-post-block%2Ftrunk%2Fplugin.php -
Summary (en) The Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the apbPosts() function hooked via an AJAX action in all versions up to, and including, 1.13.1. This makes it possible for unauthenticated attackers to retrieve all post data, including those that may be password protected. (en) The Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the apbPosts() function hooked via an AJAX action in all versions up to, and including, 1.13.4. This makes it possible for unauthenticated attackers to retrieve all post data, including those that may be password protected.

21 Nov 2024, 08:47

Type Values Removed Values Added
Summary
  • (es) El complemento Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page para WordPress es vulnerable al acceso no autorizado a los datos debido a una falta de verificación de capacidad en la función apbPosts() conectada mediante una acción AJAX en todas las versiones hasta, y incluyendo, 1.13.1. Esto hace posible que atacantes no autenticados recuperen todos los datos de las publicaciones, incluidos aquellos que pueden estar protegidos con contraseña.
References () https://plugins.trac.wordpress.org/browser/advanced-post-block/trunk/plugin.php#L173 - () https://plugins.trac.wordpress.org/browser/advanced-post-block/trunk/plugin.php#L173 -
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/8fb6c221-d885-42b5-977c-39e8608e3e31?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/8fb6c221-d885-42b5-977c-39e8608e3e31?source=cve -

02 May 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-02 17:15

Updated : 2026-04-15 00:35


NVD link : CVE-2024-0908

Mitre link : CVE-2024-0908

CVE.ORG link : CVE-2024-0908


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization