← WordPress Vulnerabilities
WordPress security by component

Post Grid and Gutenberg Blocks

Post Grid and Gutenberg Blocks is a WordPress component with 28 published CVE records in this archive. The latest tracked vulnerability was published Dec 24, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: post-grid

CVE-2025-68605: Post Grid and Gutenberg Blocks: Cross-site scripting

Post Grid and Gutenberg Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedDec 24, 2025
Safe version guidanceSee mitigation notes
Safe version
Dec 24, 2025 CVE-2025-68605
Post Grid and Gutenberg Blocks: Cross-site scripting
Post Grid and Gutenberg Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Dec 18, 2025 CVE-2025-66058
Post Grid and Gutenberg Blocks: A security weakness
Post Grid and Gutenberg Blocks is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Dec 18, 2025 CVE-2025-63043
Post Grid and Gutenberg Blocks: A security weakness
Post Grid and Gutenberg Blocks is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Oct 27, 2025 CVE-2025-62924
Post Grid and Gutenberg Blocks: A security weakness
Post Grid and Gutenberg Blocks is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Aug 20, 2025 CVE-2025-54007
Post Grid and Gutenberg Blocks: Code execution
Post Grid and Gutenberg Blocks is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
May 15, 2025 CVE-2024-9645
Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry: Cross-site scripting
Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Feb 28, 2025 CVE-2024-13796
Post Grid and Gutenberg Blocks – ComboBlocks: Sensitive information exposure
Post Grid and Gutenberg Blocks – ComboBlocks is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVD7.5
Jan 24, 2025 CVE-2024-13408
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget: Filesystem traversal
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVD8.8
Jan 15, 2025 CVE-2024-9636
Post Grid and Gutenberg Blocks: Privilege escalation or authentication bypass
Post Grid and Gutenberg Blocks is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Oct 28, 2024 CVE-2024-50432
Post Grid and Gutenberg Blocks: Cross-site scripting
Post Grid and Gutenberg Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Oct 16, 2024 CVE-2021-4450
Post Grid: SQL injection
Post Grid is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVDPending
Oct 06, 2024 CVE-2024-47340
Post Grid and Gutenberg Blocks: Cross-site scripting
Post Grid and Gutenberg Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Sep 11, 2024 CVE-2024-8253
Post Grid and Gutenberg Blocks: Privilege escalation or authentication bypass
Post Grid and Gutenberg Blocks is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Aug 12, 2024 CVE-2024-43155
ComboBlocks: Cross-site scripting
ComboBlocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Aug 01, 2024 CVE-2024-6346
Gutenberg Blocks, Page Builder – ComboBlocks: Cross-site scripting
Gutenberg Blocks, Page Builder – ComboBlocks is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 07, 2024 CVE-2024-1988
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks: Cross-site scripting
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 24, 2024 CVE-2024-32816
Post Grid: A security weakness
Post Grid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Apr 11, 2024 CVE-2024-0881
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel: A security weakness
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Mar 29, 2024 CVE-2024-30441
Post Grid: Cross-site scripting
Post Grid is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Mar 12, 2024 CVE-2023-7072
Post Grid Combo – 36+ Gutenberg Blocks: Sensitive information exposure
Post Grid Combo – 36+ Gutenberg Blocks is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE7.5
NVDPending
Nov 30, 2023 CVE-2023-40211
Post Grid Combo – 36+ Gutenberg Blocks: A security weakness
Post Grid Combo – 36+ Gutenberg Blocks is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Apr 11, 2022 CVE-2022-0447
Post Grid: Cross-site scripting
Post Grid is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD6.4
Apr 11, 2022 CVE-2021-24986
Post Grid: Cross-site scripting
Post Grid is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 02, 2021 CVE-2021-24488
slider import search feature and tab parameter of the Post Grid: Cross-site scripting
slider import search feature and tab parameter of the Post Grid is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jan 01, 2021 CVE-2020-35939
Post Grid: Code execution
Post Grid is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVD8.8
Jan 01, 2021 CVE-2020-35938
Post Grid: Code execution
Post Grid is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVD8.8
Jan 01, 2021 CVE-2020-35937
Post Grid: Cross-site scripting
Post Grid is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.5
NVD8.0
Jan 01, 2021 CVE-2020-35936
Post Grid: Cross-site scripting
Post Grid is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.5
NVD8.0