CVE Database /
CVE-2025-54007
CVE · High
CVE-2025-54007 — Post Grid [post-grid] < 2.3.12
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-54007
|
Post Grid [post-grid] < 2.3.12 |
Deserialization of Untrusted Data |
High
8.8
|
< 2.3.12
|
2.3.12 |
2025-08-06 |
—
|
CVE-2025-54007
The Post Grid and Gutenberg Blocks WordPress plugin contains a vulnerability that allows authenticated users with contributor-level access or higher to inject malicious PHP objects through untrusted input deserialization in versions up to 2.3.11. This flaw can be exploited by an additional plugin or theme on the same system, potentially leading to file deletion, data retrieval, or code execution.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings