CVE Database /
CVE-2025-30814
CVE · High
CVE-2025-30814 — The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid [the-post-grid] < 7.7.18
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-30814
|
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid [the-post-grid] < 7.7.18 |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') |
High
7.5
|
< 7.7.18
|
7.7.18 |
2025-03-27 |
—
|
CVE-2025-30814
The Post Grid plugin for WordPress contains a security flaw that allows attackers with contributor-level access or higher to inject arbitrary server-side files into the application's workflow. This vulnerability enables the execution of any PHP code within those injected files, posing risks such as unauthorized data retrieval and code injection. Affected versions include all up to 7.7.17.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings