CVE · Medium

CVE-2024-47340 — Post Grid [post-grid] < 2.2.90

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-47340 Post Grid [post-grid] < 2.2.90 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.2.90 2.2.90 2024-09-27

CVE-2024-47340

The Post Grid and Gutenberg Blocks plugin through version 2.2.89 contains a stored cross-site scripting flaw caused by inadequate sanitization of user inputs and lack of proper output encoding. Attackers with contributor-level permissions or higher can inject malicious scripts into pages that will run whenever those pages are viewed by other users. This vulnerability affects authenticated users with lower-level access roles and above.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.