CVE · High

CVE-2025-30814 — The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid [the-post-grid] < 7.7.18

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-30814 The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid [the-post-grid] < 7.7.18 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 7.5 < 7.7.18 7.7.18 2025-03-27

CVE-2025-30814

The Post Grid plugin for WordPress contains a security flaw that allows attackers with contributor-level access or higher to inject arbitrary server-side files into the application's workflow. This vulnerability enables the execution of any PHP code within those injected files, posing risks such as unauthorized data retrieval and code injection. Affected versions include all up to 7.7.17.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.