WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

The easiest and most useful plugin to display blog posts, pages, or custom posts in beautiful post layouts like post grid, post carousel & post slider

7Reported vulnerabilities
8.8Highest CVSS score
1.8Latest version
900+Active installs

What to do now

Update Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget to 1.8.1 or later. 7 of these have a fixed version available. Updating resolves them.

Plugin last updated: June 9, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-13409 High 8.8 0.9% Before 1.7 1.7 January 24, 2025
CVE-2024-2006 High 8.8 1.2% Before 1.6.8 1.6.8 March 13, 2024
CVE-2025-24782 High 8.8 0.5% 1.6.10 and earlier 1.7 January 27, 2025
CVE-2024-13408 High 8.8 0.6% Before 1.7 1.7 January 24, 2025
CVE-2022-1266 Medium 4.8 0.6% Before 1.5.0 1.5.0 June 20, 2022
CVE-2026-16260 Medium 6.4 0.3% 1.8.0 and earlier 1.8.1 August 20, 2026
CVE-2024-29925 Medium 6.4 0.3% 1.6.6 and earlier 1.6.7 March 25, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.