İçeriğe atla
Noroxi

Post Grid

post-grid · eklenti

Post Grid için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.

23 bilinen açık

2 kritik · 9 kayıt giriş yapmadan sömürülebilir · 1 kayıt için istismar kodu yayımlanmış · son kayıt 5 Eyl 2026

wordpress.org'da yayında · son sürüm 2.3.24 · son güncelleme 19 Tem 2026 · 30 bin+ kurulum

wordpress.org durumu 2 Eki 2026 tarihinde kontrol edildi

Güvenlik açıkları

  • CVE-2024-11080kimlik doğrulamasız≤ 2.3.32

    Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection

    Kritik 9.8
  • CVE-2024-9636kimlik doğrulamasız≤ 2.3.3

    Post Grid and Gutenberg Blocks 2.2.85 - 2.3.3 - Unauthenticated Privilege Escalation

    Kritik 9.8
  • CVE-2025-54007giriş gerekir≤ 2.3.11

    WordPress Post Grid and Gutenberg Blocks Plugin <= 2.3.11 - PHP Object Injection Vulnerability

    Yüksek 8.8
  • CVE-2024-8253abone+≤ 2.2.90

    Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation

    Yüksek 8.8
  • CVE-2024-13796kimlik doğrulamasız≤ 2.3.6

    Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure

    Yüksek 7.5
  • CVE-2024-32816kimlik doğrulamasız≤ 2.2.78

    WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerability

    Yüksek 7.5
  • CVE-2023-7072kimlik doğrulamasız≤ 2.2.68

    Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint

    Yüksek 7.5
  • CVE-2023-40211kimlik doğrulamasız≤ 2.2.50

    WordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data Exposure

    Yüksek 7.5
  • CVE-2024-30441kimlik doğrulamasız · tıklama gerekir≤ 2.2.74

    WordPress Combo Blocks plugin <= 2.2.74 - Reflected Cross Site Scripting (XSS) vulnerability

    Yüksek 7.1
  • CVE-2025-68605giriş gerekir≤ 2.3.23

    WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.23 - Cross Site Scripting (XSS) vulnerability

    Orta 6.5
  • CVE-2025-66058giriş gerekir≤ 2.3.17

    WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.17 - Broken Access Control vulnerability

    Orta 6.5
  • CVE-2025-62924giriş gerekir≤ 2.3.17

    WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.17 - Broken Access Control vulnerability

    Orta 6.5
  • CVE-2024-50432giriş gerekir≤ 2.2.93

    WordPress Post Grid and Gutenberg Blocks plugin <= 2.2.93 - Cross Site Scripting (XSS) vulnerability

    Orta 6.5
  • CVE-2024-47340giriş gerekir≤ 2.2.89

    WordPress ComboBlocks plugin <= 2.2.89 - Cross Site Scripting (XSS) vulnerability

    Orta 6.5
  • CVE-2024-43155giriş gerekir≤ 2.2.86

    WordPress ComboBlocks plugin <= 2.2.86 - Cross Site Scripting (XSS) vulnerability

    Orta 6.5
  • CVE-2024-7588katılımcı+≤ 2.2.84

    Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block

    Orta 6.4
  • CVE-2024-3155katılımcı+≤ 2.2.80

    Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scr

    Orta 6.4
  • CVE-2024-6346katılımcı+≤ 2.2.85

    Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scr

    Orta 5.4
  • CVE-2024-4042katılımcı+≤ 2.2.80

    Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scr

    Orta 5.4
  • CVE-2024-1988katılımcı+≤ 2.2.80

    Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scr

    Orta 5.4
  • CVE-2023-6645katılımcı+≤ 2.2.64

    Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.64 - Authenticated (Contributor+) Cross-Site Scripting

    Orta 5.4
  • CVE-2025-63043kimlik doğrulamasız≤ 2.3.23

    WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.23 - Insecure Direct Object References (IDOR) vulnerability

    Orta 5.3
  • CVE-2024-13798kimlik doğrulamasız≤ 2.3.5

    Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation

    Orta 5.3

Yetki etiketi kaydın kendi metninden okunur (ör. “abone+”: abone ve üstü roller). Metin rol söylemiyorsa CVSS'e göre “giriş gerekir” ya da “yüksek yetki” yazılır; rol adı uydurulmaz. “Tıklama gerekir”: saldırı, oturumu açık birinin bağlantıya tıklamasına bağlı (CSRF, yansıyan XSS).

← Dizine dön