WP Vulnerability WatchVulnerability data as of September 7, 2026

Vulnerability alerts / September 5, 2026

Vulnerability in Post Grid — CVE-2024-11080

CriticalSeverity
CVSS 9.8
0.4%Estimated exploit probability
EPSS
30,000+ sitesInstalls
2.3.33Fixed in

What to do now

Update Post Grid to 2.3.33 or later.

Affected versions

  • 2.2.85 to 2.3.32 (inclusive)

Affected: Post Grid (plugin, post-grid)

Check: The plugin on wordpress.org / Our record for Post Grid

What the vulnerability is

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress, granted no other security controls are present in the function.

This description is reproduced verbatim from the public vulnerability record.

Sources

See other alerts