Richard Holder
Jun 18, 2024 12:29 AM 1 Answers
Hello.  We recently had a Pentest performed on our website.  We've set our security block all rest API calls except if authenticated.  However, combo blocks does not support this security feature.  Could you please confirm?

Here is some detail from the pen tester:


How to reproduce
Issue the following command within a terminal console:
$ curl --data a
{% raw %} { {% endraw
Vulnerability description
An unauthenticated POST request to the /wp-json/post-grid/v2/get_site_data endpoint of a
WordPress site reveals the admin email address. This vulnerability allows an attacker to obtain the email
address of the site's administrator without needing to authenticate, potentially leading to further targeted

Risk description
The exposure of the WordPress admin email address is a significant security risk. Attackers can use this
information to launch targeted phishing attacks, social engineering campaigns, or brute-force attacks to
compromise the admin account. Once an attacker gains access to the admin account, they can potentially
take over the entire WordPress site, leading to data breaches, defacement, or further exploitation of the
site and its users.
To mitigate this vulnerability, it is recommended to:
1. Restrict access to the /wp-json/post-grid/v2/get_site_data endpoint to authenticated users
2. Review and update the WordPress and plugin settings to ensure that sensitive information is not
exposed through APIs.
3. Implement additional security measures such as rate limiting, IP whitelisting, and Web Application
Firewalls (WAF) to protect against unauthorized access.
4. Regularly update WordPress and its plugins to the latest versions to benefit from security patches and



Azizul Raju
Jun 23, 2024

Hi Richard,
Thank you for informing us about the security issue.

Our team has already fixed the problem and released a new version 2.2.84. Please update your plugin to the latest version, and feel free to contact us if you have any questions.

Have you had a chance to explore the newly added Gutenberg support? We've added over 50 Gutenberg blocks for you to use in your block editor!

