plugin

Post Grid Vulnerabilities

69 known security issues reported for the Post Grid WordPress plugin. Most recent disclosed Dec 24, 2025.

2 critical 5 high 22 medium

Running Post Grid on your site? Check whether your installed version is affected.

Scan your site free

Post Grid [post-grid] <= 2.3.18 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.18.

Affected:
up to 2.3.18
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68605 on NVD →

Post Grid and Gutenberg Blocks <= 2.3.21 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 2.3.21
Fix:
No patched version reported
Disclosed:
Dec 21, 2025

CVE-2025-68605 on NVD →

Post Grid [post-grid] <= 2.3.19 (unfixed)

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.3.19.

Affected:
up to 2.3.19
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-63043 on NVD →

Post Grid [post-grid] <= 2.3.17 (unfixed)

unknown

[en] Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.3.17.

Affected:
up to 2.3.17
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-66058 on NVD →

Post Grid and Gutenberg Blocks <= 2.3.19 - Unauthenticated Insecure Direct Object Reference

medium

The Post Grid plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.19 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.3.19
Fix:
No patched version reported
Disclosed:
Dec 3, 2025

CVE-2025-63043 on NVD →

Post Grid [post-grid] <= 2.3.17 (unfixed)

unknown

[en] Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.17.

Affected:
up to 2.3.17
Fix:
No patched version reported
Disclosed:
Oct 27, 2025

CVE-2025-62924 on NVD →

Post Grid and Gutenberg Blocks <= 2.3.17 - Missing Authorization

medium

The Post Grid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.17. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.3.17
Fixed in:
2.3.18
Disclosed:
Oct 4, 2025

CVE-2025-66058 on NVD →

Post Grid and Gutenberg Blocks <= 2.3.17 - Missing Authorization

medium

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.3.17. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.3.17
Fixed in:
2.3.18
Disclosed:
Oct 4, 2025

CVE-2025-62924 on NVD →

Post Grid [post-grid] < 2.3.12

unknown

[en] Deserialization of Untrusted Data vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Object Injection. This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.3.11.

Affected:
up to 2.3.12
Fixed in:
2.3.12
Disclosed:
Aug 20, 2025

CVE-2025-54007 on NVD →

Post Grid and Gutenberg Blocks <= 2.3.11 - Authenticated (Contributor+) PHP Object Injection

high

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.11 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is presen...

CVSS:
8.8
Affected:
up to 2.3.11
Fixed in:
2.3.12
Disclosed:
Aug 6, 2025

CVE-2025-54007 on NVD →

Post Grid [post-grid] < 2.3.7

unknown

[en] The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.6 via the /wp-json/post-grid/v2/get_users REST API This makes it possible for unauthenticated attackers to extract sensitive data including including email...

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Feb 28, 2025

CVE-2024-13796 on NVD →

Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure

medium

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.6 via the /wp-json/post-grid/v2/get_users REST API This makes it possible for unauthenticated attackers to extract sensitive data including including emails and...

CVSS:
5.3
Affected:
up to 2.3.6
Fixed in:
2.3.7
Disclosed:
Feb 27, 2025

CVE-2024-13796 on NVD →

Post Grid [post-grid] < 2.3.6

unknown

[en] The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. This is due to insufficient verification on form fields. This makes it possible for unauthenticated attackers to create new orders for products and mark th...

Affected:
up to 2.3.6
Fixed in:
2.3.6
Disclosed:
Feb 22, 2025

CVE-2024-13798 on NVD →

Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation

medium

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. This is due to insufficient verification on form fields. This makes it possible for unauthenticated attackers to create new orders for products and mark them as...

CVSS:
5.3
Affected:
up to 2.3.5
Fixed in:
2.3.6
Disclosed:
Feb 21, 2025

CVE-2024-13798 on NVD →

Post Grid and Gutenberg Blocks 2.2.85 - 2.3.3 - Unauthenticated Privilege Escalation

critical

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible for unauthenticated attackers to register on the site as an admi...

CVSS:
9.8
Affected:
2.2.85 – 2.3.3
Fixed in:
2.3.4
Disclosed:
Jan 14, 2025

CVE-2024-9636 on NVD →

Post Grid and Gutenberg Blocks <= 2.2.92 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.92 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 2.2.92
Fixed in:
2.2.93
Disclosed:
Jan 14, 2025

CVE-2024-9645 on NVD →

Post Grid [post-grid] < 2.2.94

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.2.93.

Affected:
up to 2.2.94
Fixed in:
2.2.94
Disclosed:
Oct 28, 2024

CVE-2024-50432 on NVD →

Post Grid and Gutenberg Blocks <= 2.2.93 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.93 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 2.2.93
Fixed in:
2.2.94
Disclosed:
Oct 24, 2024

CVE-2024-50432 on NVD →

Post Grid [post-grid] < 2.1.13

unknown

[en] The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contr...

Affected:
up to 2.1.13
Fixed in:
2.1.13
Disclosed:
Oct 16, 2024

CVE-2021-4450 on NVD →

Post Grid [post-grid] < 2.2.90

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.2.89.

Affected:
up to 2.2.90
Fixed in:
2.2.90
Disclosed:
Oct 6, 2024

CVE-2024-47340 on NVD →

Post Grid and Gutenberg Blocks <= 2.2.89 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.89 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 2.2.89
Fixed in:
2.2.90
Disclosed:
Sep 27, 2024

CVE-2024-47340 on NVD →

Post Grid [post-grid] < 2.2.91

unknown

[en] The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting what user meta values can be updated and ensuring a form is active. This makes it possible for authenticated attackers, with subscriber-...

Affected:
up to 2.2.91
Fixed in:
2.2.91
Disclosed:
Sep 11, 2024

CVE-2024-8253 on NVD →

Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation

high

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting what user meta values can be updated and ensuring a form is active. This makes it possible for authenticated attackers, with subscriber-level...

CVSS:
8.8
Affected:
2.2.87 – 2.2.90
Fixed in:
2.2.91
Disclosed:
Sep 10, 2024

CVE-2024-8253 on NVD →

Post Grid [post-grid] < 2.2.88

unknown

[en] The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion block in all versions up to, and including, 2.2.87 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...

Affected:
up to 2.2.88
Fixed in:
2.2.88
Disclosed:
Aug 14, 2024

CVE-2024-7588 on NVD →

Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block

medium

The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion block in all versions up to, and including, 2.2.87 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate...

CVSS:
6.4
Affected:
up to 2.2.84
Fixed in:
2.2.88
Disclosed:
Aug 13, 2024

CVE-2024-7588 on NVD →

Post Grid [post-grid] < 2.2.87

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins ComboBlocks allows Stored XSS.This issue affects ComboBlocks: from n/a through 2.2.86.

Affected:
up to 2.2.87
Fixed in:
2.2.87
Disclosed:
Aug 12, 2024

CVE-2024-43155 on NVD →

ComboBlocks <= 2.2.86 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several blocks in versions up to, and including, 2.2.86 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and abov...

CVSS:
6.4
Affected:
up to 2.2.86
Fixed in:
2.2.87
Disclosed:
Aug 7, 2024

CVE-2024-43155 on NVD →

Post Grid [post-grid] < 2.2.86

unknown

[en] The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the redirectURL parameter of the Date Countdown widget, in all versions up to, and including, 2.2.85a due to insufficient input sanitization and output escaping on user supplied attributes. This m...

Affected:
up to 2.2.86
Fixed in:
2.2.86
Disclosed:
Aug 1, 2024

CVE-2024-6346 on NVD →

Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget

medium

The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the redirectURL parameter of the Date Countdown widget, in all versions up to, and including, 2.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i...

CVSS:
6.4
Affected:
up to 2.2.85
Fixed in:
2.2.86
Disclosed:
Jul 31, 2024

CVE-2024-6346 on NVD →

Post Grid [post-grid] < 2.2.81

unknown

[en] The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute in blocks in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. This mak...

Affected:
up to 2.2.81
Fixed in:
2.2.81
Disclosed:
Jun 7, 2024

CVE-2024-1988 on NVD →

Post Grid [post-grid] < 2.2.81

unknown

[en] The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the menu-wrap-item block in all versions up to, and including, 2.2.80 due to insufficient input sanitization and outpu...

Affected:
up to 2.2.81
Fixed in:
2.2.81
Disclosed:
Jun 7, 2024

CVE-2024-4042 on NVD →

Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute in blocks in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. This makes it...

CVSS:
6.4
Affected:
up to 2.2.80
Fixed in:
2.2.81
Disclosed:
Jun 6, 2024

CVE-2024-1988 on NVD →

Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute

medium

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the menu-wrap-item block in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output esc...

CVSS:
6.4
Affected:
up to 2.2.80
Fixed in:
2.2.81
Disclosed:
Jun 6, 2024

CVE-2024-4042 on NVD →

Post Grid [post-grid] < 2.2.81

unknown

[en] The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. This makes it possi...

Affected:
up to 2.2.81
Fixed in:
2.2.81
Disclosed:
May 21, 2024

CVE-2024-3155 on NVD →

Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. This makes it possible f...

CVSS:
6.4
Affected:
up to 2.2.80
Fixed in:
2.2.81
Disclosed:
May 20, 2024

CVE-2024-3155 on NVD →

Post Grid [post-grid] < 2.2.79

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid.This issue affects Post Grid: from n/a through 2.2.78.

Affected:
up to 2.2.79
Fixed in:
2.2.79
Disclosed:
Apr 24, 2024

CVE-2024-32816 on NVD →

Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.78 - Unauthenticated Sensitive Information Exposure

medium

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.78. This makes it possible for unauthenticated attackers to extract sensitive information.

CVSS:
5.3
Affected:
up to 2.2.78
Fixed in:
2.2.79
Disclosed:
Apr 22, 2024

CVE-2024-32816 on NVD →

Post Grid [post-grid] < 2.2.76

unknown

[en] The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

Affected:
up to 2.2.76
Fixed in:
2.2.76
Disclosed:
Apr 11, 2024

CVE-2024-0881 on NVD →

Post Grid [post-grid] < 2.2.76

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid allows Reflected XSS.This issue affects Post Grid: from n/a through 2.2.74.

Affected:
up to 2.2.76
Fixed in:
2.2.76
Disclosed:
Mar 29, 2024

CVE-2024-30441 on NVD →

Post Grid <= 2.2.74 - Reflected Cross-Site Scripting

medium

The Post Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.74 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...

CVSS:
6.1
Affected:
up to 2.2.74
Fixed in:
2.2.76
Disclosed:
Mar 28, 2024

CVE-2024-30441 on NVD →

Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel <= 2.2.74 - Information Exposure

medium

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.74 via the post_grid_paginate_ajax_free AJAX endpoint. This makes it possible for unauthenticated attackers to retrieve pr...

CVSS:
5.3
Affected:
up to 2.2.74
Fixed in:
2.2.76
Disclosed:
Mar 19, 2024

CVE-2024-0881 on NVD →

Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint

high

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 via the 'get_posts' REST API Endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including full draft posts and password prote...

CVSS:
7.5
Affected:
up to 2.2.68
Fixed in:
2.2.69
Disclosed:
Mar 12, 2024

CVE-2023-7072 on NVD →

Post Grid [post-grid] < 2.2.69

unknown

[en] The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 via the 'get_posts' REST API Endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including full draft posts and password...

Affected:
up to 2.2.69
Fixed in:
2.2.69
Disclosed:
Mar 12, 2024

CVE-2023-7072 on NVD →

Post Grid [post-grid] < 2.2.65

unknown

[en] The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.2.64 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor acce...

Affected:
up to 2.2.65
Fixed in:
2.2.65
Disclosed:
Jan 11, 2024

CVE-2023-6645 on NVD →

Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.64 - Authenticated (Contributor+) Cross-Site Scripting

medium

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.2.64 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or...

CVSS:
6.4
Affected:
up to 2.2.64
Fixed in:
2.2.65
Disclosed:
Dec 15, 2023

CVE-2023-6645 on NVD →

Post Grid [post-grid] < 2.2.51

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.

Affected:
up to 2.2.51
Fixed in:
2.2.51
Disclosed:
Nov 30, 2023

CVE-2023-40211 on NVD →

Post Grid <= 2.2.50 - Missing Authorization to Sensitive Information Exposure via REST API

high

The Post Grid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple REST API endpoints in versions up to, and including, 2.2.50. This makes it possible for unauthenticated attackers to expose sensitive inforamtion.

CVSS:
7.5
Affected:
up to 2.2.50
Fixed in:
2.2.51
Disclosed:
Aug 11, 2023

CVE-2023-40211 on NVD →

Post Grid [post-grid] < 2.1.16

unknown

[en] The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form

Affected:
up to 2.1.16
Fixed in:
2.1.16
Disclosed:
Apr 11, 2022

CVE-2021-24986 on NVD →

Post Grid [post-grid] < 2.1.16

unknown

[en] The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.1.16
Fixed in:
2.1.16
Disclosed:
Apr 11, 2022

CVE-2022-0447 on NVD →

Post Grid <= 2.1.15 - Cross-Site Scripting

medium

The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form

CVSS:
6.1
Affected:
up to 2.1.16
Fixed in:
2.1.16
Disclosed:
Mar 15, 2022

CVE-2021-24986 on NVD →

Post Grid < 2.1.16 - Reflected Cross-Site Scripting

medium

The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 2.1.16
Fixed in:
2.1.16
Disclosed:
Mar 15, 2022

CVE-2022-0447 on NVD →

Post Grid <= 2.1.12 - Contributor+ SQL Injection

high

The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributo...

CVSS:
8.8
Affected:
up to 2.1.13
Fixed in:
2.1.13
Disclosed:
Dec 15, 2021

CVE-2021-4450 on NVD →

Post Grid [post-grid] < 2.1.13

unknown

The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributo...

Affected:
up to 2.1.13
Fixed in:
2.1.13
Disclosed:
Dec 15, 2021

Post Grid [post-grid] < 2.1.8

unknown

[en] The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues

Affected:
up to 2.1.8
Fixed in:
2.1.8
Disclosed:
Aug 2, 2021

CVE-2021-24488 on NVD →

Post Grid <= 2.1.7 - Reflected Cross-Site Scripting

medium

The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues

CVSS:
6.1
Affected:
up to 2.1.7
Fixed in:
2.1.8
Disclosed:
Jun 28, 2021

CVE-2021-24488 on NVD →

Post Grid [post-grid] < 2.0.73

unknown

[en] Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.

Affected:
up to 2.0.73
Fixed in:
2.0.73
Disclosed:
Jan 1, 2021

CVE-2020-35936 on NVD →

Post Grid [post-grid] < 2.0.73

unknown

[en] PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_i...

Affected:
up to 2.0.73
Fixed in:
2.0.73
Disclosed:
Jan 1, 2021

CVE-2020-35938 on NVD →

Post Grid [post-grid] < 2.0.73

unknown

[en] PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_i...

Affected:
up to 2.0.73
Fixed in:
2.0.73
Disclosed:
Jan 1, 2021

CVE-2020-35939 on NVD →

Post Grid [post-grid] < 2.0.73

unknown

[en] Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.

Affected:
up to 2.0.73
Fixed in:
2.0.73
Disclosed:
Jan 1, 2021

CVE-2020-35937 on NVD →

Post Grid [post-grid] < 2.0.73

unknown

PHP Object Injection vulnerability found by Ramuel Gall (Wordfence) in WordPress Post Grid plugin (versions <= 2.0.72).

Affected:
up to 2.0.73
Fixed in:
2.0.73
Disclosed:
Oct 5, 2020

Post Grid [post-grid] < 2.0.73

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Ramuel Gall in WordPress Post Grid plugin (versions <= 2.0.72).

Affected:
up to 2.0.73
Fixed in:
2.0.73
Disclosed:
Oct 5, 2020

Post Grid <= 2.0.12 - Arbitrary File Deletion

critical

The Post Grid plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.0.12. This is due to the plugin failing to properly verify user input. This makes it possible for unauthenticated attackers to delete files on the vulnerable service.

CVSS:
9.1
Affected:
up to 2.0.12
Fixed in:
2.0.13
Disclosed:
Nov 8, 2016

Post Grid [post-grid] < 2.0.13

unknown

This plugin is prone to an arbitrary file deletion vulnerability. Update the plugin.

Affected:
up to 2.0.13
Fixed in:
2.0.13
Disclosed:
Nov 8, 2016

Post Grid [post-grid] < 2.0.13

unknown

WordPress Post Grid plugin File deletion vulnerability allows any user to delete any file from the website. The vulnerbility is in post_grid_ajax_remove_export_content_layout() function. Update the plugin.

Affected:
up to 2.0.13
Fixed in:
2.0.13
Disclosed:
Nov 8, 2016

Post Grid [post-grid] < 2.0.13

unknown

The Post Grid plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.0.12. This is due to the plugin failing to properly verify user input. This makes it possible for unauthenticated attackers to delete files on the vulnerable service.

Affected:
up to 2.0.13
Fixed in:
2.0.13
Disclosed:
Nov 8, 2016

Post Grid [post-grid] >= 2.2.85 - <= 2.3.3

unknown
Affected:
2.2.85 – 2.3.3
Fixed in:
2.3.3

CVE-2024-9636 on NVD →

Post Grid [post-grid] < 2.0.13

unknown

The Post Grid WordPress plugin was affected by an Unauthenticated Arbitrary File Deletion security vulnerability.

Affected:
up to 2.0.13
Fixed in:
2.0.13

Post Grid [post-grid] < 2.1.13

unknown

The plugin does not sanitise and escape user input before using it in a SQL statement when duplicating posts (available to Contributor+ users), leading to an SQL Injection

Affected:
up to 2.1.13
Fixed in:
2.1.13

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database