Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2024-11080: Post Grid plugin lets strangers run code via hooks
CVE-2024-11080 · published 20 days ago
Summary
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress (versions 2.2.32 to 2.3.1) allows anyone on the internet to trigger WordPress actions without logging in. This could let attackers make changes or run unwanted tasks on your site. Update the plugin to the latest version or remove it until a fix is released.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| pickplugins | post grid | <= 2.3.32 |
Original advisory text
Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress, granted no other security controls are present in the function.
References
- https://plugins.trac.wordpress.org/browser/post-grid/trunk/includes/blocks/form-...
- https://plugins.trac.wordpress.org/browser/post-grid/trunk/includes/blocks/form-...
- https://plugins.trac.wordpress.org/browser/post-grid/trunk/includes/blocks/form-...
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ec8666d4-042e-4cf4-86f...
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published5 Sep 2026
Updated25 Sep 2026
First seen5 Sep 2026
Track software like this
Free during beta