Extension WordPress
Vulnérabilités The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid
Cette page rassemble les failles publiées pour The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid
12 fiches
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.9.2 – Missing Authorization
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.9.2.…
*-7.9.2
7.9.3
27/05/2026
The Post Grid <= 7.7.17 – Authenticated (Contributor+) Local File Inclusion
The The Post Grid plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.7.17. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files…
*-7.7.17
7.7.18
27/03/2025
The Post Grid <= 7.4.3 – Authenticated (Editor+) Stored Cross-Site Scripting
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.4.3 due to insufficient input…
*-7.4.3
7.5.0
09/09/2024
The Post Grid <= 7.7.11 – Authenticated (Contributor+) Information Disclosure
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.7.11 via the post_query_guten and post_query functions. This…
*-7.7.11
7.7.12
28/08/2024
The Post Grid <= 7.7.4 – Missing Authorization via REST API
The The Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints in versions up to, and including, 7.7.4. This makes it possible for unauthenticated…
*-7.7.4
7.7.5
04/07/2024
The Post Grid <= 7.7.4 – Missing Authorization via AJAX
The The Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in versions up to, and including, 7.7.4. This makes it possible for authenticated attackers,…
*-7.7.4
7.7.5
04/07/2024
The Post Grid <= 7.7.4 – Missing Authorization via save_block_css
The The Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the save_block_css() function in versions up to, and including, 7.7.4. This makes it possible for authenticated attackers,…
*-7.7.4
7.7.5
04/07/2024
The Post Grid <= 7.7.1 – Authenticated(Contributor+) Stored Cross-Site Scripting via section title tag
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attribute in all versions up to, and including, 7.7.1 due…
*-7.7.1
7.7.2
01/07/2024
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.7.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output…
*-7.7.1
7.7.2
06/06/2024
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.6.1 – Missing Authorization
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtTPGSaveSettings function in all versions up…
*-7.6.1
7.7.0
30/04/2024
The Post Grid <= 7.2.7 – Cross-Site Request Forgery
The The Post Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.2.7. This is due to missing or incorrect nonce validation on the save_block_css() function. This makes it possible for…
*-7.2.7
7.2.8
07/08/2023
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 5.0.4 – Cross-Site Request Forgery in rttpg_spare_me
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.0.4. This is due to missing or incorrect nonce…
*-5.0.4
5.0.5
20/02/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.