Cross-Site Scripting
15 records51.7%First: 2021. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 29 vulnerability records associated with Post Grid, published between 2016 and 2025.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2016 | 1 | |
| 2021 | 2 | |
| 2022 | 2 | |
| 2023 | 2 | |
| 2024 | 13 | |
| 2025 | 9 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 6.9% |
| High | 5 | 17.2% |
| Medium | 22 | 75.9% |
First: 2021. Latest: 2025.
First: 2023. Latest: 2025.
First: 2024. Latest: 2025.
First: 2024. Latest: 2025.
First: 2025. Latest: 2025.
First: 2016. Latest: 2016.
First: 2021. Latest: 2021.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
2.3.182.3.122.3.72.3.62.3.42.2.932.2.942.2.902.2.912.2.882.2.872.2.862.2.812.2.792.2.762.2.692.2.652.2.512.1.162.1.132.1.82.0.13Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.3.21 | Post Grid and Gutenberg Blocks <= 2.3.21 - Authenticated (Contributor+) Stored Cross-Site Scripting | December 21, 2025 | Not supplied | Medium |
*-2.3.19 | Post Grid and Gutenberg Blocks <= 2.3.19 - Unauthenticated Insecure Direct Object Reference | December 3, 2025 | Not supplied | Medium |
*-2.3.17 | Post Grid and Gutenberg Blocks <= 2.3.17 - Missing Authorization | October 4, 2025 | 2.3.18 | Medium |
*-2.3.17 | Post Grid and Gutenberg Blocks <= 2.3.17 - Missing Authorization | October 4, 2025 | 2.3.18 | Medium |
*-2.3.11 | Post Grid and Gutenberg Blocks <= 2.3.11 - Authenticated (Contributor+) PHP Object Injection | August 6, 2025 | 2.3.12 | High |
*-2.3.6 | Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure | February 27, 2025 | 2.3.7 | Medium |
*-2.3.5 | Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation | February 21, 2025 | 2.3.6 | Medium |
2.2.85-2.3.3 | Post Grid and Gutenberg Blocks 2.2.85 - 2.3.3 - Unauthenticated Privilege Escalation | January 14, 2025 | 2.3.4 | Critical |
*-2.2.92 | Post Grid and Gutenberg Blocks <= 2.2.92 - Authenticated (Contributor+) Stored Cross-Site Scripting | January 14, 2025 | 2.2.93 | Medium |
*-2.2.93 | Post Grid and Gutenberg Blocks <= 2.2.93 - Authenticated (Contributor+) Stored Cross-Site Scripting | October 24, 2024 | 2.2.94 | Medium |
*-2.2.89 | Post Grid and Gutenberg Blocks <= 2.2.89 - Authenticated (Contributor+) Stored Cross-Site Scripting | September 27, 2024 | 2.2.90 | Medium |
2.2.87-2.2.90 | Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation | September 10, 2024 | 2.2.91 | High |
*-2.2.84 | Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block | August 13, 2024 | 2.2.88 | Medium |
*-2.2.86 | ComboBlocks <= 2.2.86 - Authenticated (Contributor+) Stored Cross-Site Scripting | August 7, 2024 | 2.2.87 | Medium |
*-2.2.85 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget | July 31, 2024 | 2.2.86 | Medium |
*-2.2.80 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting | June 6, 2024 | 2.2.81 | Medium |
*-2.2.80 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute | June 6, 2024 | 2.2.81 | Medium |
*-2.2.80 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting | May 20, 2024 | 2.2.81 | Medium |
*-2.2.78 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.78 - Unauthenticated Sensitive Information Exposure | April 22, 2024 | 2.2.79 | Medium |
*-2.2.74 | Post Grid <= 2.2.74 - Reflected Cross-Site Scripting | March 28, 2024 | 2.2.76 | Medium |
*-2.2.74 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel <= 2.2.74 - Information Exposure | March 19, 2024 | 2.2.76 | Medium |
*-2.2.68 | Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint | March 12, 2024 | 2.2.69 | High |
*-2.2.64 | Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.64 - Authenticated (Contributor+) Cross-Site Scripting | December 15, 2023 | 2.2.65 | Medium |
*-2.2.50 | Post Grid <= 2.2.50 - Missing Authorization to Sensitive Information Exposure via REST API | August 11, 2023 | 2.2.51 | High |
[*, 2.1.16) | Post Grid < 2.1.16 - Reflected Cross-Site Scripting | March 15, 2022 | 2.1.16 | Medium |
Selected source records
Published: December 21, 2025
Published: December 3, 2025
Published: October 4, 2025
Published: October 4, 2025
Published: August 6, 2025
Published: February 27, 2025
Published: February 21, 2025
Published: January 14, 2025
Published: January 14, 2025
Published: November 8, 2016
Published: December 15, 2021
Published: August 6, 2025
Published: September 10, 2024
Published: August 11, 2023
Published: March 12, 2024
Published: July 31, 2024
Published: December 21, 2025
Published: December 3, 2025
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.