The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.9.2 - Missing Authorization
medium
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.9.2. This makes it possible for authenticated attackers, with contributor-level access and above...
- CVSS:
- 4.3
- Affected:
- up to 7.9.2
- Fixed in:
- 7.9.3
- Disclosed:
- May 27, 2026
CVE-2026-49054 on NVD →
The Post Grid <= 7.7.17 - Authenticated (Contributor+) Local File Inclusion
high
The The Post Grid plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.7.17. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files....
- CVSS:
- 8.8
- Affected:
- up to 7.7.17
- Fixed in:
- 7.7.18
- Disclosed:
- Mar 27, 2025
CVE-2025-30814 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks, Divi Modules and Elementor Addon for Post Grid [the-post-grid] < 7.7.18
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme The Post Grid allows PHP Local File Inclusion. This issue affects The Post Grid: from n/a through 7.7.17.
- Affected:
- up to 7.7.18
- Fixed in:
- 7.7.18
- Disclosed:
- Mar 27, 2025
CVE-2025-30814 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks, Divi Modules and Elementor Addon for Post Grid [the-post-grid] < 7.7.5
unknown
[en] Missing Authorization vulnerability in Post Grid Team by RadiusTheme The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Post Grid: from n/a through 7.7.4.
- Affected:
- up to 7.7.5
- Fixed in:
- 7.7.5
- Disclosed:
- Nov 1, 2024
CVE-2024-37482 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks, Divi Modules and Elementor Addon for Post Grid [the-post-grid] < 7.7.5
unknown
[en] Missing Authorization vulnerability in Post Grid Team by RadiusTheme The Post Grid allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects The Post Grid: from n/a through 7.7.4.
- Affected:
- up to 7.7.5
- Fixed in:
- 7.7.5
- Disclosed:
- Nov 1, 2024
CVE-2024-37481 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks, Divi Modules and Elementor Addon for Post Grid [the-post-grid] < 7.7.5
unknown
[en] Missing Authorization vulnerability in Post Grid Team by RadiusTheme The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Post Grid: from n/a through 7.7.4.
- Affected:
- up to 7.7.5
- Fixed in:
- 7.7.5
- Disclosed:
- Nov 1, 2024
CVE-2024-37483 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks, Divi Modules and Elementor Addon for Post Grid [the-post-grid] < 7.5.0
unknown
[en] The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 7.5.0
- Fixed in:
- 7.5.0
- Disclosed:
- Sep 30, 2024
CVE-2024-3635 on NVD →
The Post Grid <= 7.4.3 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...
- CVSS:
- 4.4
- Affected:
- up to 7.4.3
- Fixed in:
- 7.5.0
- Disclosed:
- Sep 9, 2024
CVE-2024-3635 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks, Divi Modules and Elementor Addon for Post Grid [the-post-grid] < 7.7.12
unknown
[en] The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.7.11 via the post_query_guten and post_query functions. This makes it possible for authenticated attackers, with contributor...
- Affected:
- up to 7.7.12
- Fixed in:
- 7.7.12
- Disclosed:
- Aug 29, 2024
CVE-2024-7418 on NVD →
The Post Grid <= 7.7.11 - Authenticated (Contributor+) Information Disclosure
medium
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.7.11 via the post_query_guten and post_query functions. This makes it possible for authenticated attackers, with contributor-leve...
- CVSS:
- 4.3
- Affected:
- up to 7.7.11
- Fixed in:
- 7.7.12
- Disclosed:
- Aug 28, 2024
CVE-2024-7418 on NVD →
The Post Grid <= 7.7.4 - Missing Authorization via REST API
medium
The The Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints in versions up to, and including, 7.7.4. This makes it possible for unauthenticated attackers to perform several unauthorized actions.
- CVSS:
- 5.3
- Affected:
- up to 7.7.4
- Fixed in:
- 7.7.5
- Disclosed:
- Jul 4, 2024
CVE-2024-37481 on NVD →
The Post Grid <= 7.7.4 - Missing Authorization via save_block_css
medium
The The Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the save_block_css() function in versions up to, and including, 7.7.4. This makes it possible for authenticated attackers, with contributor-level access and above, to save block CSS.
- CVSS:
- 4.3
- Affected:
- up to 7.7.4
- Fixed in:
- 7.7.5
- Disclosed:
- Jul 4, 2024
CVE-2024-37483 on NVD →
The Post Grid <= 7.7.4 - Missing Authorization via AJAX
medium
The The Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in versions up to, and including, 7.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform various unauthorized actions...
- CVSS:
- 4.3
- Affected:
- up to 7.7.4
- Fixed in:
- 7.7.5
- Disclosed:
- Jul 4, 2024
CVE-2024-37482 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks, Divi Modules and Elementor Addon for Post Grid [the-post-grid] < 7.7.2
unknown
[en] The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attribute in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping on user supplied attributes....
- Affected:
- up to 7.7.2
- Fixed in:
- 7.7.2
- Disclosed:
- Jul 2, 2024
CVE-2024-1427 on NVD →
The Post Grid <= 7.7.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via section title tag
medium
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attribute in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This...
- CVSS:
- 6.4
- Affected:
- up to 7.7.1
- Fixed in:
- 7.7.2
- Disclosed:
- Jul 1, 2024
CVE-2024-1427 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks, Divi Modules and Elementor Addon for Post Grid [the-post-grid] < 7.7.2
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RadiusTheme The Post Grid allows Stored XSS.This issue affects The Post Grid: from n/a through 7.7.1.
- Affected:
- up to 7.7.2
- Fixed in:
- 7.7.2
- Disclosed:
- Jun 8, 2024
CVE-2024-35739 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 7.7.1
- Fixed in:
- 7.7.2
- Disclosed:
- Jun 6, 2024
CVE-2024-35739 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks, Divi Modules and Elementor Addon for Post Grid [the-post-grid] < 7.7.0
unknown
[en] The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtTPGSaveSettings function in all versions up to, and including, 7.6.1. This makes it possible for authenticated attacke...
- Affected:
- up to 7.7.0
- Fixed in:
- 7.7.0
- Disclosed:
- May 2, 2024
CVE-2024-3936 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.6.1 - Missing Authorization
medium
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtTPGSaveSettings function in all versions up to, and including, 7.6.1. This makes it possible for authenticated attackers, w...
- CVSS:
- 4.3
- Affected:
- up to 7.6.1
- Fixed in:
- 7.7.0
- Disclosed:
- Apr 30, 2024
CVE-2024-3936 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks, Divi Modules and Elementor Addon for Post Grid [the-post-grid] < 7.2.8
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 7.2.7 versions.
- Affected:
- up to 7.2.8
- Fixed in:
- 7.2.8
- Disclosed:
- Oct 3, 2023
CVE-2023-39923 on NVD →
The Post Grid <= 7.2.7 - Cross-Site Request Forgery
medium
The The Post Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.2.7. This is due to missing or incorrect nonce validation on the save_block_css() function. This makes it possible for unauthenticated attackers to modify block CSS via a forged request granted they ca...
- CVSS:
- 4.3
- Affected:
- up to 7.2.7
- Fixed in:
- 7.2.8
- Disclosed:
- Aug 7, 2023
CVE-2023-39923 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks, Divi Modules and Elementor Addon for Post Grid [the-post-grid] < 5.0.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 5.0.4 versions.
- Affected:
- up to 5.0.5
- Fixed in:
- 5.0.5
- Disclosed:
- May 23, 2023
CVE-2022-46853 on NVD →
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 5.0.4 - Cross-Site Request Forgery in rttpg_spare_me
medium
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.0.4. This is due to missing or incorrect nonce validation on the rttpg_spare_me function. This makes it possible for unauthenticated atta...
- CVSS:
- 4.3
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.5
- Disclosed:
- Feb 20, 2023
CVE-2022-46853 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database