Post Grid
PickPlugins · 15 CVEs
Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection
Sep 5, 2026
Post Grid and Gutenberg Blocks < 2.2.93 - Contributor+ Stored XSS
May 15, 2025
Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure
Feb 28, 2025
Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation
Feb 22, 2025
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (C…
Jan 24, 2025
Post Grid <= 2.1.12 - Contributor+ SQL Injection
Oct 16, 2024
Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation
Sep 11, 2024
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.85 - Authentic…
Aug 1, 2024
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks <= 2.2.80 - Authentic…
Jun 7, 2024
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authentic…
Jun 7, 2024
WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerability
Apr 24, 2024
Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access
Apr 11, 2024
WordPress Combo Blocks plugin <= 2.2.74 - Reflected Cross Site Scripting (XSS) vulnerability
Mar 29, 2024
Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types
Apr 11, 2022
Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keyword
Apr 11, 2022
Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
Aug 2, 2021
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticate…
Jan 1, 2021
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated att…
Jan 1, 2021
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote…
Jan 1, 2021
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote auth…
Jan 1, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-11080 | Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection | CRITICAL | 0.45% | Sep 5, 2026 |
| CVE-2024-9645 | Post Grid and Gutenberg Blocks < 2.2.93 - Contributor+ Stored XSS | MEDIUM | 0.30% | May 15, 2025 |
| CVE-2024-13796 | Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure | HIGH | 0.44% | Feb 28, 2025 |
| CVE-2024-13798 | Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation | MEDIUM | 0.33% | Feb 22, 2025 |
| CVE-2024-13408 | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion | HIGH | 0.59% | Jan 24, 2025 |
| CVE-2021-4450 | Post Grid <= 2.1.12 - Contributor+ SQL Injection | HIGH | 0.49% | Oct 16, 2024 |
| CVE-2024-8253 | Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation | HIGH | 9.37% | Sep 11, 2024 |
| CVE-2024-6346 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Sc… | MEDIUM | 0.32% | Aug 1, 2024 |
| CVE-2024-4042 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Sc… | MEDIUM | 0.26% | Jun 7, 2024 |
| CVE-2024-1988 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Sc… | MEDIUM | 0.26% | Jun 7, 2024 |
| CVE-2024-32816 | WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerability | HIGH | 0.68% | Apr 24, 2024 |
| CVE-2024-0881 | Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access | MEDIUM | 16.91% | Apr 11, 2024 |
| CVE-2024-30441 | WordPress Combo Blocks plugin <= 2.2.74 - Reflected Cross Site Scripting (XSS) vulnerability | HIGH | 0.38% | Mar 29, 2024 |
| CVE-2022-0447 | Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types | MEDIUM | 0.64% | Apr 11, 2022 |
| CVE-2021-24986 | Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keyword | MEDIUM | 0.80% | Apr 11, 2022 |
| CVE-2021-24488 | Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS) | MEDIUM | 11.24% | Aug 2, 2021 |
| CVE-2020-35939 | PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP obje… | HIGH | 2.11% | Jan 1, 2021 |
| CVE-2020-35938 | PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects d… | HIGH | 2.11% | Jan 1, 2021 |
| CVE-2020-35937 | Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layou… | HIGH | 1.67% | Jan 1, 2021 |
| CVE-2020-35936 | Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts in… | HIGH | 1.67% | Jan 1, 2021 |
Showing 1 to 15 of 15 CVEs