Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Post Grid — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Post Grid, with AI-generated Chinese analysis, references, and POCs.

This is the vulnerability aggregation page for Post Grid, a WordPress plugin that provides grid-based layouts. It collects a comprehensive inventory of security flaws affecting this specific plugin, covering the full historical record from its initial release through the latest patch. Visitors can use this page to track vendor advisories, analyze the prevalence of specific weakness classes such as cross-site scripting or SQL injection, and review the product's complete vulnerability history. The data is organized to help security teams identify recurring patterns in the codebase and assess the risk exposure of deployed instances. By centralizing these records, the page supports efficient auditing and remediation planning for organizations relying on Post Grid for their website presentation layer. No single CVE is highlighted here; instead, the focus remains on the aggregate trend and the structural security posture of the plugin over time. This resource serves as a factual reference for compliance checks and long-term maintenance strategies, ensuring that users can make informed decisions about updates and mitigations without wading through scattered individual reports.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2024-11080 Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection CWE-94 9.8 Critical 2026-09-05
CVE-2024-13796 Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure CWE-200 5.3 Medium 2025-02-28
CVE-2024-13798 Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation CWE-20 5.3 Medium 2025-02-22
CVE-2021-4450 Post Grid <= 2.1.12 - Contributor+ SQL Injection CWE-89 8.8 High 2024-10-16
CVE-2024-7588 Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block CWE-79 6.4 Medium 2024-08-14
CVE-2024-6346 Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget CWE-79 6.4 Medium 2024-08-01
CVE-2024-4042 Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute CWE-79 6.4 Medium 2024-06-07
CVE-2024-1988 Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-06-07
CVE-2024-3155 Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-05-21
CVE-2024-32816 WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerability CWE-200 7.5 High 2024-04-24
CVE-2024-30441 WordPress Combo Blocks plugin <= 2.2.74 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-03-29
CVE-2023-7072 Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint CWE-202 7.5 High 2024-03-12
CVE-2023-6645 Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.64 - Authenticated (Contributor+) Cross-Site Scripting CWE-79 6.4 Medium 2024-01-11
CVE-2022-0447 Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types CWE-79 5.4 - 2022-04-11
CVE-2021-24986 Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keyword CWE-79 6.1 - 2022-04-11
CVE-2021-24488 Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS) CWE-79 6.1 - 2021-08-02

All 16 known CVE vulnerabilities affecting Post Grid with full Chinese analysis, references, and POCs where available.