cleantalk
Vulnerabilities and Security Researches

Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks, 7b1bc9ba2311d3e49ca5be34d5300122c25fe8d2

Published on
Nov 08, 2016
Research Description
Post Grid [post-grid] < 2.0.13 Post Grid <= 2.0.12 - Arbitrary File Deletion The Post Grid plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.0.12. This is due to the plugin failing to properly verify user input. This makes it possible for unauthenticated attackers to delete files on the vulnerable service.
Affected versions
max 2.0.13.
Status
vulnerable