Post Grid
post-grid · eklenti
Post Grid için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
23 bilinen açık
2 kritik · 9 kayıt giriş yapmadan sömürülebilir · 1 kayıt için istismar kodu yayımlanmış · son kayıt 5 Eyl 2026
wordpress.org'da yayında · son sürüm 2.3.24 · son güncelleme 19 Tem 2026 · 30 bin+ kurulum
wordpress.org durumu 2 Eki 2026 tarihinde kontrol edildi
Güvenlik açıkları
- Kritik 9.8
CVE-2024-11080kimlik doğrulamasız≤ 2.3.32
Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection
- Kritik 9.8
CVE-2024-9636kimlik doğrulamasız≤ 2.3.3
Post Grid and Gutenberg Blocks 2.2.85 - 2.3.3 - Unauthenticated Privilege Escalation
- Yüksek 8.8
CVE-2025-54007giriş gerekir≤ 2.3.11
WordPress Post Grid and Gutenberg Blocks Plugin <= 2.3.11 - PHP Object Injection Vulnerability
- Yüksek 8.8
CVE-2024-8253abone+≤ 2.2.90
Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation
- Yüksek 7.5
CVE-2024-13796kimlik doğrulamasız≤ 2.3.6
Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure
- Yüksek 7.5
CVE-2024-32816kimlik doğrulamasız≤ 2.2.78
WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerability
- Yüksek 7.5
CVE-2023-7072kimlik doğrulamasız≤ 2.2.68
Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint
- Yüksek 7.5
CVE-2023-40211kimlik doğrulamasız≤ 2.2.50
WordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data Exposure
- Yüksek 7.1
CVE-2024-30441kimlik doğrulamasız · tıklama gerekir≤ 2.2.74
WordPress Combo Blocks plugin <= 2.2.74 - Reflected Cross Site Scripting (XSS) vulnerability
- Orta 6.5
CVE-2025-68605giriş gerekir≤ 2.3.23
WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.23 - Cross Site Scripting (XSS) vulnerability
- Orta 6.5
CVE-2025-66058giriş gerekir≤ 2.3.17
WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.17 - Broken Access Control vulnerability
- Orta 6.5
CVE-2025-62924giriş gerekir≤ 2.3.17
WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.17 - Broken Access Control vulnerability
- Orta 6.5
CVE-2024-50432giriş gerekir≤ 2.2.93
WordPress Post Grid and Gutenberg Blocks plugin <= 2.2.93 - Cross Site Scripting (XSS) vulnerability
- Orta 6.5
CVE-2024-47340giriş gerekir≤ 2.2.89
WordPress ComboBlocks plugin <= 2.2.89 - Cross Site Scripting (XSS) vulnerability
- Orta 6.5
CVE-2024-43155giriş gerekir≤ 2.2.86
WordPress ComboBlocks plugin <= 2.2.86 - Cross Site Scripting (XSS) vulnerability
- Orta 6.4
CVE-2024-7588katılımcı+≤ 2.2.84
Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block
- Orta 6.4
CVE-2024-3155katılımcı+≤ 2.2.80
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scr
- Orta 5.4
CVE-2024-6346katılımcı+≤ 2.2.85
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scr
- Orta 5.4
CVE-2024-4042katılımcı+≤ 2.2.80
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scr
- Orta 5.4
CVE-2024-1988katılımcı+≤ 2.2.80
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scr
- Orta 5.4
CVE-2023-6645katılımcı+≤ 2.2.64
Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.64 - Authenticated (Contributor+) Cross-Site Scripting
- Orta 5.3
CVE-2025-63043kimlik doğrulamasız≤ 2.3.23
WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.23 - Insecure Direct Object References (IDOR) vulnerability
- Orta 5.3
CVE-2024-13798kimlik doğrulamasız≤ 2.3.5
Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation
Yetki etiketi kaydın kendi metninden okunur (ör. “abone+”: abone ve üstü roller). Metin rol söylemiyorsa CVSS'e göre “giriş gerekir” ya da “yüksek yetki” yazılır; rol adı uydurulmaz. “Tıklama gerekir”: saldırı, oturumu açık birinin bağlantıya tıklamasına bağlı (CSRF, yansıyan XSS).