Grid Plus – Unlimited grid layout [grid-plus] <= 3.3 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Grid Plus grid-plus allows Reflected XSS.This issue affects Grid Plus: from n/a through <= 3.3.
- Affected:
- up to 3.3
- Fix:
- No patched version reported
- Disclosed:
- Oct 22, 2025
CVE-2025-53352 on NVD →
Grid Plus <= 3.3 - Reflected Cross-Site Scripting
medium
The Grid Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...
- CVSS:
- 6.1
- Affected:
- up to 3.3
- Fix:
- No patched version reported
- Disclosed:
- Sep 13, 2025
CVE-2025-53352 on NVD →
Grid Plus – Unlimited grid layout [grid-plus] < 1.3.3 (closed)
unknown
[en] Missing Authorization vulnerability in G5Theme Grid Plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grid Plus: from n/a through 1.3.2.
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Dec 13, 2024
CVE-2023-34014 on NVD →
Grid Plus – Unlimited grid layout [grid-plus] <= 1.3.5 (unfixed + closed)
unknown
[en] The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_plus_load_by_category AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before runnin...
- Affected:
- up to 1.3.5
- Fix:
- No patched version reported
- Disclosed:
- Dec 12, 2024
CVE-2024-10910 on NVD →
Grid Plus – Unlimited grid layout <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via grid_plus_load_by_category
high
The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_plus_load_by_category AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_...
- CVSS:
- 7.3
- Affected:
- up to 1.3.5
- Fix:
- No patched version reported
- Disclosed:
- Dec 11, 2024
CVE-2024-10910 on NVD →
Grid Plus – Unlimited grid layout [grid-plus] < 1.3.4 (closed)
unknown
[en] The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.2 via a shortcode attribute. This allows subscriber-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be use...
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- Oct 30, 2023
CVE-2023-5250 on NVD →
Grid Plus – Unlimited grid layout [grid-plus] < 1.3.3 (closed)
unknown
[en] The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'grid_plus_save_layout_callback' and 'grid_plus_delete_callback' functions in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with...
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Oct 30, 2023
CVE-2023-5251 on NVD →
Grid Plus <= 1.3.3 - Authenticated (Subscriber+) Local File Inclusion via Shortcode
high
The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a shortcode attribute. This allows subscriber-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to...
- CVSS:
- 8.8
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.4
- Disclosed:
- Oct 29, 2023
CVE-2023-5250 on NVD →
Grid Plus <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Grid Layout Add/Update/Delete
medium
The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'grid_plus_save_layout_callback' and 'grid_plus_delete_callback' functions in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with subs...
- CVSS:
- 5.4
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.3
- Disclosed:
- Oct 29, 2023
CVE-2023-5251 on NVD →
Grid Plus – Unlimited grid layout [grid-plus] < 1.3.3 (closed)
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in G5Theme Grid Plus – Unlimited grid plugin <= 1.3.2 versions.
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Oct 27, 2023
CVE-2023-46209 on NVD →
Grid Plus <= 1.3.4 - Reflected Cross-Site Scripting via grid_id
medium
The Grid Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘grid_id’ parameter in versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.5
- Disclosed:
- Oct 19, 2023
CVE-2023-46209 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database