CVE-2020-35936, CVE-2020-35937
The Post Grid plugin before version 2.0.73 contains stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious JavaScript code through the layout import functionality. By crafting a malicious payload hosted remotely and specifying it in the source parameter during an AJAX request with the post_grid_import_xml_layouts action, an attacker can import layouts containing executable scripts that persist in the WordPress installation. This vulnerability affects all versions prior to 2.0.73 and requires administrator-level access to exploit.
Based on public CVE data (MITRE/NVD).