Post Grid and Gutenberg Blocks
Post Grid and Gutenberg Blocks displays WordPress posts in configurable grid layouts with filtering, pagination, and customizable content presentation.
Post Grid and Gutenberg Blocks (post-grid) is a WordPress plugin with 29 published CVE records in this archive. The latest tracked vulnerability was published Sep 05, 2026; the highest published CVSS base score is 9.8.
post-gridCVE-2024-11080: Post Grid permits unauthenticated WordPress hook execution
Post Grid exposes several functions in includes/blocks/form-wrap/function.php to unauthenticated hook injection. An attacker can invoke WordPress actions where the selected hook lacks its own security control. The authoritative description says versions 2.2.32 through 2.3.1 are affected, while its machine-readable affected range says 2.2.85 through 2.3.32; that source inconsistency remains unresolved.
| Safe version |
|
||
|---|---|---|---|
| Sep 05, 2026 |
CVE-2024-11080
Post Grid permits unauthenticated WordPress hook execution
Post Grid exposes several functions in includes/blocks/form-wrap/function.php to unauthenticated hook injection. An attacker can invoke WordPress actions where the selected hook lacks its own security control. The authoritative description says versions 2.2.32 through 2.3.1 are affected, while its machine-readable affected range says 2.2.85 through 2.3.32; that source inconsistency remains unresolved.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Dec 24, 2025 |
CVE-2025-68605
Post Grid and Gutenberg Blocks: Cross-site scripting
Post Grid and Gutenberg Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 18, 2025 |
CVE-2025-66058
Post Grid and Gutenberg Blocks: A security weakness
Post Grid and Gutenberg Blocks is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 18, 2025 |
CVE-2025-63043
Post Grid and Gutenberg Blocks: A security weakness
Post Grid and Gutenberg Blocks is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Oct 27, 2025 |
CVE-2025-62924
Post Grid and Gutenberg Blocks: A security weakness
Post Grid and Gutenberg Blocks is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 20, 2025 |
CVE-2025-54007
Post Grid and Gutenberg Blocks: Code execution
Post Grid and Gutenberg Blocks is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVDPending
|
| May 15, 2025 |
CVE-2024-9645
Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry: Cross-site scripting
Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Feb 28, 2025 |
CVE-2024-13796
Post Grid and Gutenberg Blocks – ComboBlocks: Sensitive information exposure
Post Grid and Gutenberg Blocks – ComboBlocks is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Jan 24, 2025 |
CVE-2024-13408
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget: Filesystem traversal
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget is affected by filesystem traversal. Exploitation requires an authenticated contributor account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVD8.8
|
| Jan 15, 2025 |
CVE-2024-9636
Post Grid and Gutenberg Blocks: Privilege escalation or authentication bypass
Post Grid and Gutenberg Blocks is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Oct 28, 2024 |
CVE-2024-50432
Post Grid and Gutenberg Blocks: Cross-site scripting
Post Grid and Gutenberg Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 16, 2024 |
CVE-2021-4450
Post Grid: SQL injection
Post Grid is affected by SQL injection. Exploitation requires an authenticated contributor account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Oct 06, 2024 |
CVE-2024-47340
Post Grid and Gutenberg Blocks: Cross-site scripting
Post Grid and Gutenberg Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Sep 11, 2024 |
CVE-2024-8253
Post Grid and Gutenberg Blocks: Privilege escalation or authentication bypass
Post Grid and Gutenberg Blocks is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated subscriber account. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Aug 12, 2024 |
CVE-2024-43155
ComboBlocks: Cross-site scripting
ComboBlocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 01, 2024 |
CVE-2024-6346
Gutenberg Blocks, Page Builder – ComboBlocks: Cross-site scripting
Gutenberg Blocks, Page Builder – ComboBlocks is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jun 07, 2024 |
CVE-2024-1988
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks: Cross-site scripting
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 24, 2024 |
CVE-2024-32816
Post Grid: A security weakness
Post Grid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Apr 11, 2024 |
CVE-2024-0881
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel: A security weakness
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Mar 29, 2024 |
CVE-2024-30441
Post Grid: Cross-site scripting
Post Grid is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Mar 12, 2024 |
CVE-2023-7072
Post Grid Combo – 36+ Gutenberg Blocks: Sensitive information exposure
Post Grid Combo – 36+ Gutenberg Blocks is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Nov 30, 2023 |
CVE-2023-40211
Post Grid Combo – 36+ Gutenberg Blocks: A security weakness
Post Grid Combo – 36+ Gutenberg Blocks is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Apr 11, 2022 |
CVE-2022-0447
Post Grid: Cross-site scripting
Post Grid is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.4
|
| Apr 11, 2022 |
CVE-2021-24986
Post Grid: Cross-site scripting
Post Grid is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Aug 02, 2021 |
CVE-2021-24488
slider import search feature and tab parameter of the Post Grid: Cross-site scripting
slider import search feature and tab parameter of the Post Grid is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jan 01, 2021 |
CVE-2020-35939
Post Grid: Code execution
Post Grid is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.5
NVD8.8
|
| Jan 01, 2021 |
CVE-2020-35938
Post Grid: Code execution
Post Grid is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.5
NVD8.8
|
| Jan 01, 2021 |
CVE-2020-35937
Post Grid: Cross-site scripting
Post Grid is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.5
NVD8.0
|
| Jan 01, 2021 |
CVE-2020-35936
Post Grid: Cross-site scripting
Post Grid is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.5
NVD8.0
|