PickPlugins Post Grid and Gutenberg Blocks - ComboBlocks
cpe:2.3:a:pickplugins:post_grid:*:*:*:*:wordpress:*:*
- <= 2.3.5
A vulnerability exists in the Post Grid and Gutenberg Blocks - ComboBlocks plugin for WordPress, allowing unauthorized order creation in all versions through 2.3.5. This issue arises from inadequate validation of form fields, enabling unauthenticated attackers to generate new product orders and mark them as paid without completing the actual payment.
Exploitation of this vulnerability allows for unauthorized creation of orders, which are falsely marked as paid, potentially leading to financial discrepancies and abuse of the ordering system.
Users are advised to update the Post Grid and Gutenberg Blocks - ComboBlocks plugin to version 2.3.6 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.