Extension WordPress

Vulnérabilités The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

Cette page rassemble les failles publiées pour The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
0Critiques
12Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

12 fiches

CVE-2026-49054 Moyenne · 4,3
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.9.2 – Missing Authorization

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.9.2.…

Versions affectées

*-7.9.2

Correctif

7.9.3

Publication

27/05/2026

CVE-2025-30814 Élevée · 8,8
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

The Post Grid <= 7.7.17 – Authenticated (Contributor+) Local File Inclusion

The The Post Grid plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.7.17. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files…

Versions affectées

*-7.7.17

Correctif

7.7.18

Publication

27/03/2025

CVE-2024-3635 Moyenne · 4,4
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

The Post Grid <= 7.4.3 – Authenticated (Editor+) Stored Cross-Site Scripting

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.4.3 due to insufficient input…

Versions affectées

*-7.4.3

Correctif

7.5.0

Publication

09/09/2024

CVE-2024-7418 Moyenne · 4,3
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

The Post Grid <= 7.7.11 – Authenticated (Contributor+) Information Disclosure

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.7.11 via the post_query_guten and post_query functions. This…

Versions affectées

*-7.7.11

Correctif

7.7.12

Publication

28/08/2024

CVE-2024-37481 Moyenne · 5,3
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

The Post Grid <= 7.7.4 – Missing Authorization via REST API

The The Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints in versions up to, and including, 7.7.4. This makes it possible for unauthenticated…

Versions affectées

*-7.7.4

Correctif

7.7.5

Publication

04/07/2024

CVE-2024-37482 Moyenne · 4,3
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

The Post Grid <= 7.7.4 – Missing Authorization via AJAX

The The Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in versions up to, and including, 7.7.4. This makes it possible for authenticated attackers,…

Versions affectées

*-7.7.4

Correctif

7.7.5

Publication

04/07/2024

CVE-2024-37483 Moyenne · 4,3
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

The Post Grid <= 7.7.4 – Missing Authorization via save_block_css

The The Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the save_block_css() function in versions up to, and including, 7.7.4. This makes it possible for authenticated attackers,…

Versions affectées

*-7.7.4

Correctif

7.7.5

Publication

04/07/2024

CVE-2024-1427 Moyenne · 6,4
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

The Post Grid <= 7.7.1 – Authenticated(Contributor+) Stored Cross-Site Scripting via section title tag

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attribute in all versions up to, and including, 7.7.1 due…

Versions affectées

*-7.7.1

Correctif

7.7.2

Publication

01/07/2024

CVE-2024-35739 Moyenne · 6,4
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.7.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output…

Versions affectées

*-7.7.1

Correctif

7.7.2

Publication

06/06/2024

CVE-2024-3936 Moyenne · 4,3
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.6.1 – Missing Authorization

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtTPGSaveSettings function in all versions up…

Versions affectées

*-7.6.1

Correctif

7.7.0

Publication

30/04/2024

CVE-2022-46853 Moyenne · 4,3
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 5.0.4 – Cross-Site Request Forgery in rttpg_spare_me

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.0.4. This is due to missing or incorrect nonce…

Versions affectées

*-5.0.4

Correctif

5.0.5

Publication

20/02/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités