plugin

Grid Plus Vulnerabilities

11 known security issues reported for the Grid Plus WordPress plugin. Most recent disclosed Oct 22, 2025.

2 high 3 medium

Running Grid Plus on your site? Check whether your installed version is affected.

Scan your site free

Grid Plus &#8211; Unlimited grid layout [grid-plus] <= 3.3 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Grid Plus grid-plus allows Reflected XSS.This issue affects Grid Plus: from n/a through <= 3.3.

Affected:
up to 3.3
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-53352 on NVD →

Grid Plus <= 3.3 - Reflected Cross-Site Scripting

medium

The Grid Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

CVSS:
6.1
Affected:
up to 3.3
Fix:
No patched version reported
Disclosed:
Sep 13, 2025

CVE-2025-53352 on NVD →

Grid Plus &#8211; Unlimited grid layout [grid-plus] < 1.3.3 (closed)

unknown

[en] Missing Authorization vulnerability in G5Theme Grid Plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grid Plus: from n/a through 1.3.2.

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Dec 13, 2024

CVE-2023-34014 on NVD →

Grid Plus &#8211; Unlimited grid layout [grid-plus] <= 1.3.5 (unfixed + closed)

unknown

[en] The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_plus_load_by_category AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before runnin...

Affected:
up to 1.3.5
Fix:
No patched version reported
Disclosed:
Dec 12, 2024

CVE-2024-10910 on NVD →

Grid Plus – Unlimited grid layout <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via grid_plus_load_by_category

high

The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_plus_load_by_category AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_...

CVSS:
7.3
Affected:
up to 1.3.5
Fix:
No patched version reported
Disclosed:
Dec 11, 2024

CVE-2024-10910 on NVD →

Grid Plus &#8211; Unlimited grid layout [grid-plus] < 1.3.4 (closed)

unknown

[en] The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.2 via a shortcode attribute. This allows subscriber-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be use...

Affected:
up to 1.3.4
Fixed in:
1.3.4
Disclosed:
Oct 30, 2023

CVE-2023-5250 on NVD →

Grid Plus &#8211; Unlimited grid layout [grid-plus] < 1.3.3 (closed)

unknown

[en] The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'grid_plus_save_layout_callback' and 'grid_plus_delete_callback' functions in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with...

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Oct 30, 2023

CVE-2023-5251 on NVD →

Grid Plus <= 1.3.3 - Authenticated (Subscriber+) Local File Inclusion via Shortcode

high

The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a shortcode attribute. This allows subscriber-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to...

CVSS:
8.8
Affected:
up to 1.3.3
Fixed in:
1.3.4
Disclosed:
Oct 29, 2023

CVE-2023-5250 on NVD →

Grid Plus <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Grid Layout Add/Update/Delete

medium

The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'grid_plus_save_layout_callback' and 'grid_plus_delete_callback' functions in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with subs...

CVSS:
5.4
Affected:
up to 1.3.2
Fixed in:
1.3.3
Disclosed:
Oct 29, 2023

CVE-2023-5251 on NVD →

Grid Plus &#8211; Unlimited grid layout [grid-plus] < 1.3.3 (closed)

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in G5Theme Grid Plus – Unlimited grid plugin <= 1.3.2 versions.

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Oct 27, 2023

CVE-2023-46209 on NVD →

Grid Plus <= 1.3.4 - Reflected Cross-Site Scripting via grid_id

medium

The Grid Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘grid_id’ parameter in versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 1.3.4
Fixed in:
1.3.5
Disclosed:
Oct 19, 2023

CVE-2023-46209 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database