CVE · High

CVE-2020-35936 — Post Grid [post-grid] < 2.0.73

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-35936, CVE-2020-35937 Post Grid [post-grid] < 2.0.73 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 8.0 < 2.0.73 2.0.73 2021-01-01

CVE-2020-35936, CVE-2020-35937

The Post Grid plugin before version 2.0.73 contains stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious JavaScript code through the layout import functionality. By crafting a malicious payload hosted remotely and specifying it in the source parameter during an AJAX request with the post_grid_import_xml_layouts action, an attacker can import layouts containing executable scripts that persist in the WordPress installation. This vulnerability affects all versions prior to 2.0.73 and requires administrator-level access to exploit.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.