CVE-2020-35938, CVE-2020-35939
The Post Grid plugin before version 2.0.73 contains a PHP object injection vulnerability that allows authenticated attackers to inject malicious PHP objects through unsafe unserialization of data. This flaw exists in the AJAX handler when the team_import_xml_layouts action is used with a malicious payload supplied via the source parameter. Remote attackers with authentication credentials can exploit this vulnerability to execute arbitrary code on the affected WordPress installation.
Based on public CVE data (MITRE/NVD).