Addonmaster's vulnerability footprint centers on a compact set of WordPress plugins, including Post Grid Master, Bootstrap Shortcodes Ultimate, and Load More Anything, that extend site functionality across a significant installed base. Vulnerabilities affecting these plugins skew toward serious outcomes and recur through weakness classes including cross-site scripting, missing authorization controls, PHP remote file inclusion, and path traversal—patterns characteristic of plugin-layer input handling and file-access logic. Defenders should apply patches to affected WordPress installations systematically, as the plugins' broad adoption amplifies the risk exposure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Addonmaster over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11642CRITICAL The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to | Jan 9, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-30974HIGH Missing Authorization vulnerability in Akhtarujjaman Shuvo Post Grid Master ajax-filter-posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff | Jun 6, 2025 | 8.8 | 23 | NO | NO |
CVE-2025-5084MEDIUM The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘argsArray['read_more_text']’ parameter in all versions up to, and including, 3.4. | Jul 24, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-24733MEDIUM Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Akhtarujjaman Shuvo Post Grid Master ajax-filter-posts allo | Jan 24, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-43156MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AddonMaster Post Grid Master allows Reflected XSS.This issue affects Po | Aug 12, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-24704MEDIUM Missing Authorization vulnerability in AddonMaster Load More Anything.This issue affects Load More Anything: from n/a through 3.3.3. | Jun 11, 2024 | 6.3 | 18 | NO | NO |
CVE-2024-34390MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonMaster Post Grid Master allows Stored XSS.This issue affects Post Grid Ma | May 6, 2024 | 6.5 | 18 | NO | NO |
CVE-2023-47851MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akhtarujjaman Shuvo Bootstrap Shortcodes Ultimate allows Stored XSS.This issue | Nov 30, 2023 | 5.4 | 17 | NO | NO |
CVE-2024-34372MEDIUM Missing Authorization vulnerability in AddonMaster Post Grid Master.This issue affects Post Grid Master: from n/a through 3.4.7. | May 6, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Addonmaster.
Media articles that mention a CVE ID that affects a product developed by Addonmaster — matched by CVE ID, not by vendor name.