CVE-2020-35938, CVE-2020-35939
The Post Grid plugin for WordPress versions before 2.0.73 contains a PHP object injection vulnerability that can be exploited by authenticated remote attackers. The flaw stems from unsafe unserialization of user-supplied data transmitted through the source parameter in an AJAX request directed at the post_grid_import_xml_layouts action, which could originate from a malicious external payload. This vulnerability enables attackers to inject and execute arbitrary PHP objects within the application.
Based on public CVE data (MITRE/NVD).