Post Grid
Vendor:
First CVE: Jan 1, 2021 · Active for 5 years
23
Total CVEs
More Total CVEs than 95% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Post Grid over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 2021
5 years ago
Most Recent CVE
May 15, 2025
435 days ago
CVE Severity & Scoring
Post Grid23 CVEs
52%
48%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (56.5%)
Unknown0 (0.0%)
Required10 (43.5%)
Privileges Required
Low16 (69.6%)
High0 (0.0%)
None7 (30.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24488MEDIUM The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading | Aug 2, 2021 | 6.1 | 43 | NO | YES |
CVE-2024-0881MEDIUM The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password pro | Apr 11, 2024 | 5.4 | 33 | NO | YES |
CVE-2024-8253HIGH The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting w | Sep 11, 2024 | 8.8 | 29 | NO | NO |
CVE-2020-35939HIGH PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure u | Jan 1, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-35938HIGH PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unseri | Jan 1, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-4450HIGH The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied | Oct 16, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-13408HIGH The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and | Jan 24, 2025 | 8.8 | 25 | NO | NO |
CVE-2020-35937HIGH Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScri | Jan 1, 2021 | 8.0 | 25 | NO | NO |
CVE-2020-35936HIGH Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript su | Jan 1, 2021 | 8.0 | 25 | NO | NO |
CVE-2023-7072HIGH The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 via the 'get_posts' RES | Mar 12, 2024 | 7.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
8.7% of CVEs· 97th percentile
ExploitDB
1 CVE
4.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Post Grid
Top CWEs
Versions
No cataloged versions.