VendorsPickPluginspost_gridany version
Vulnerabilities

PickPlugins Post Grid any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2024-8253
Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation
Published 2024-09-11 · Analyzed
8.8EPSS 0.094
CVE-2020-35938
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.
Published 2021-01-01 · Modified
8.8EPSS 0.021
CVE-2020-35939
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.
Published 2021-01-01 · Modified
8.8EPSS 0.021
CVE-2024-13408
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion
Published 2025-01-24 · Analyzed
8.8EPSS 0.006
CVE-2021-4450
Post Grid <= 2.1.12 - Contributor+ SQL Injection
Published 2024-10-16 · Analyzed
8.8EPSS 0.005
CVE-2020-35936
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.
Published 2021-01-01 · Modified
8.0EPSS 0.017
CVE-2020-35937
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.
Published 2021-01-01 · Modified
8.0EPSS 0.017
CVE-2024-13796
Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure
Published 2025-02-28 · Analyzed
7.5EPSS 0.004
CVE-2022-0447
Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types
Published 2022-04-11 · Modified
6.4EPSS 0.006
CVE-2024-1988
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-06-07 · Modified
6.4EPSS 0.003
CVE-2021-24488
Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
Published 2021-08-02 · Modified
6.11 PoCEPSS 0.112
CVE-2021-24986
Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keyword
Published 2022-04-11 · Modified
6.1EPSS 0.008
CVE-2024-0881
Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access
Published 2024-04-11 · Analyzed
5.4EPSS 0.169
CVE-2024-9645
Post Grid and Gutenberg Blocks < 2.2.93 - Contributor+ Stored XSS
Published 2025-05-15 · Analyzed
5.4EPSS 0.003