WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.23 - Insecure Direct Object References (IDOR) vulnerability
Post Grid
Minimum safe version
2.3.18
Update to 2.3.18 or later to address 37 fixable vulnerabilities
CVE-2025-66058
WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.23 - Cross Site Scripting (XSS) vulnerability
CVE-2025-62924
CVE-2025-54007
Post Grid and Gutenberg Blocks <= 2.2.92 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2024-13796
CVE-2024-13798
WordPress Post Grid and Gutenberg Blocks Plugin 2.2.85-2.3.3 is vulnerable to Privilege Escalation
CVE-2024-50432
CVE-2021-4450
CVE-2024-47340
CVE-2024-8253
CVE-2024-7588
CVE-2024-43155
CVE-2024-6346
CVE-2024-1988
CVE-2024-4042
CVE-2024-3155
CVE-2024-32816
WordPress Post Grid Plugin < 2.2.76 is vulnerable to Broken Access Control
CVE-2024-30441
CVE-2023-7072
WordPress Post Grid Plugin <= 2.2.64 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-40211
Post Grid <= 2.0.12 - Unauthenticated Arbitrary File Deletion
CVE-2020-35939
CVE-2020-35937
Post Grid < 2.1.13 - Contributor+ SQL Injection
Post Grid <= 2.0.12 - Arbitrary File Deletion
Post Grid <= 2.1.12 - Contributor+ SQL Injection
WordPress Post Grid Plugin <= 2.0.11 - File Deletion Vulnerability
WordPress Post Grid Plugin <= 2.0.12 - Arbitrary File Deletion
WordPress Post Grid plugin <= 2.0.72 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress Post Grid plugin <= 2.0.72 - PHP Object Injection vulnerability
CVE-2021-24986
CVE-2022-0447
CVE-2020-35936
CVE-2020-35938
CVE-2021-24488