CVE · High

CVE-2020-35939 — Post Grid [post-grid] < 2.0.73

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-35938, CVE-2020-35939 Post Grid [post-grid] < 2.0.73 Deserialization of Untrusted Data High 8.8 < 2.0.73 2.0.73 2021-01-01

CVE-2020-35938, CVE-2020-35939

The Post Grid plugin before version 2.0.73 contains a PHP object injection vulnerability that allows authenticated attackers to inject malicious PHP objects through unsafe unserialization of data. This flaw exists in the AJAX handler when the team_import_xml_layouts action is used with a malicious payload supplied via the source parameter. Remote attackers with authentication credentials can exploit this vulnerability to execute arbitrary code on the affected WordPress installation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.