PLUGIN SECURITY
Is Post Grid safe?
Post Grid is a powerful WordPress plugin for creating customizable post grid layouts with advanced query options, allowing users to display posts dyna …
What this plugin does
- Slug:
post-grid - Author: PickPlugins
- 30000+ active installs
- 86/100 rating (163 reviews on wordpress.org)
- 3477441 all-time downloads
- On WordPress.org since 2015-02-06
post filterpost gridPost Masonryposts carouselposts slider
Maintenance status
- Latest known version: 2.3.24
- Last updated: 2026-07-19 3:09am GMT
- Tested up to WordPress: 7.0.4
Known vulnerabilities
32 known CVEs on file for Post Grid.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Post Grid [post-grid] <= 2.3.23 (unfixed) | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2.3.23 | 2.3.23 | 2025-12-21 | ✓ fixed in latest |
| — | Post Grid [post-grid] <= 2.3.23 (unfixed) | Authorization Bypass Through User-Controlled Key | Unknown | < 2.3.23 | 2.3.23 | 2025-12-03 | ✓ fixed in latest |
| CVE-2025-62924 | Post Grid [post-grid] < 2.3.18 | Missing Authorization | High 8.8 | < 2.3.18 | 2.3.18 | 2025-10-04 | ✓ fixed in latest |
| CVE-2025-66058 | Post Grid [post-grid] < 2.3.18 | Missing Authorization | Unknown | < 2.3.18 | 2.3.18 | 2025-10-04 | ✓ fixed in latest |
| CVE-2025-54007 | Post Grid [post-grid] < 2.3.12 | Deserialization of Untrusted Data | High 8.8 | < 2.3.12 | 2.3.12 | 2025-08-06 | ✓ fixed in latest |
| CVE-2024-13796 | Post Grid [post-grid] < 2.3.7 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 2.3.7 | 2.3.7 | 2025-02-27 | ✓ fixed in latest |
| CVE-2024-13798 | Post Grid [post-grid] < 2.3.6 | Improper Input Validation | Medium 5.3 | < 2.3.6 | 2.3.6 | 2025-02-21 | ✓ fixed in latest |
| CVE-2024-50432 | Post Grid [post-grid] < 2.2.94 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2.2.94 | 2.2.94 | 2024-10-24 | ✓ fixed in latest |
+ 37 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-47340 | Post Grid [post-grid] < 2.2.90 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2.2.90 | 2.2.90 | 2024-09-27 | ✓ fixed in latest |
| CVE-2024-8253 | Post Grid [post-grid] < 2.2.91 | Incorrect Privilege Assignment | High 8.8 | < 2.2.91 | 2.2.91 | 2024-09-10 | ✓ fixed in latest |
| CVE-2024-7588 | Post Grid [post-grid] < 2.2.88 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.2.88 | 2.2.88 | 2024-08-13 | ✓ fixed in latest |
| CVE-2024-43155 | Post Grid [post-grid] < 2.2.87 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2.2.87 | 2.2.87 | 2024-08-07 | ✓ fixed in latest |
| CVE-2024-6346 | Post Grid [post-grid] < 2.2.86 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.2.86 | 2.2.86 | 2024-07-31 | ✓ fixed in latest |
| CVE-2024-4042 | Post Grid [post-grid] < 2.2.81 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.2.81 | 2.2.81 | 2024-06-06 | ✓ fixed in latest |
| CVE-2024-1988 | Post Grid [post-grid] < 2.2.81 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.2.81 | 2.2.81 | 2024-06-06 | ✓ fixed in latest |
| CVE-2024-3155 | Post Grid [post-grid] < 2.2.81 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | Medium 6.4 | < 2.2.81 | 2.2.81 | 2024-05-20 | ✓ fixed in latest |
| CVE-2024-32816 | Post Grid [post-grid] < 2.2.79 | Exposure of Sensitive Information to an Unauthorized Actor | High 7.5 | < 2.2.79 | 2.2.79 | 2024-04-22 | ✓ fixed in latest |
| CVE-2024-30441 | Post Grid [post-grid] < 2.2.76 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 2.2.76 | 2.2.76 | 2024-03-28 | ✓ fixed in latest |
| CVE-2024-0881 | Post Grid [post-grid] < 2.2.76 | Incorrect Authorization | Medium 5.4 | < 2.2.76 | 2.2.76 | 2024-03-19 | ✓ fixed in latest |
| CVE-2023-7072 | Post Grid [post-grid] < 2.2.69 | Exposure of Sensitive Information Through Data Queries | High 7.5 | < 2.2.69 | 2.2.69 | 2024-03-12 | ✓ fixed in latest |
| CVE-2023-6645 | Post Grid [post-grid] < 2.2.65 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.2.65 | 2.2.65 | 2023-12-15 | ✓ fixed in latest |
| CVE-2023-40211 | Post Grid [post-grid] < 2.2.51 | Exposure of Sensitive Information to an Unauthorized Actor | High 7.5 | < 2.2.51 | 2.2.51 | 2023-08-11 | ✓ fixed in latest |
| CVE-2022-0447 | Post Grid [post-grid] < 2.1.16 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.1.16 | 2.1.16 | 2022-03-15 | ✓ fixed in latest |
| CVE-2021-24986 | Post Grid [post-grid] < 2.1.16 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.1.16 | 2.1.16 | 2022-03-15 | ✓ fixed in latest |
| CVE-2021-4450 | Post Grid [post-grid] < 2.1.13 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 2.1.13 | 2.1.13 | 2021-12-15 | ✓ fixed in latest |
| CVE-2021-24488 | Post Grid [post-grid] < 2.1.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.1.8 | 2.1.8 | 2021-06-28 | ✓ fixed in latest |
| CVE-2020-35938, CVE-2020-35939 | Post Grid [post-grid] < 2.0.73 | Deserialization of Untrusted Data | High 8.8 | < 2.0.73 | 2.0.73 | 2021-01-01 | ✓ fixed in latest |
| CVE-2020-35936, CVE-2020-35937 | Post Grid [post-grid] < 2.0.73 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 8.0 | < 2.0.73 | 2.0.73 | 2021-01-01 | ✓ fixed in latest |
| CVE-2020-35937 | Post Grid [post-grid] < 2.0.73 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 8.0 | < 2.0.73 | 2.0.73 | 2021-01-01 | ✓ fixed in latest |
| CVE-2020-35939 | Post Grid [post-grid] < 2.0.73 | Deserialization of Untrusted Data | High 8.8 | < 2.0.73 | 2.0.73 | 2021-01-01 | ✓ fixed in latest |
| — | Post Grid [post-grid] < 2.0.73 | — | Unknown | < 2.0.73 | 2.0.73 | 2020-10-05 | ✓ fixed in latest |
| — | Post Grid [post-grid] < 2.0.73 | — | Unknown | < 2.0.73 | 2.0.73 | 2020-10-05 | ✓ fixed in latest |
| — | Post Grid [post-grid] < 2.0.13 | — | Unknown | < 2.0.13 | 2.0.13 | 2016-11-08 | ✓ fixed in latest |
| — | Post Grid [post-grid] < 2.0.13 | — | Unknown | < 2.0.13 | 2.0.13 | 2016-11-08 | ✓ fixed in latest |
| — | Post Grid [post-grid] < 2.0.13 | — | Unknown | < 2.0.13 | 2.0.13 | 2016-11-08 | ✓ fixed in latest |
| — | Post Grid [post-grid] >= 2.2.85 - < 2.3.4 | Improper Privilege Management | Critical 9.8 | 2.2.85–2.3.4 | 2.3.4 | 0000-00-00 | ✓ fixed in latest |
| — | Post Grid [post-grid] < 2.2.93 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.2.93 | 2.2.93 | 0000-00-00 | ✓ fixed in latest |
| — | Post Grid [post-grid] < 2.1.13 | — | Unknown | < 2.1.13 | 2.1.13 | — | ✓ fixed in latest |
| — | Post Grid [post-grid] < 2.0.13 | — | Unknown | < 2.0.13 | 2.0.13 | — | ✓ fixed in latest |
| — | Post Grid <= 2.0.12 - Unauthenticated Arbitrary File Deletion | — | Unknown | < 2.0.13 | 2.0.13 | — | ✓ fixed in latest |
| — | Post Grid < 2.1.13 - Contributor+ SQL Injection | — | Unknown | < 2.1.13 | 2.1.13 | — | ✓ fixed in latest |
| CVE-2024-9645 | Post Grid and Gutenberg Blocks < 2.2.93 - Contributor+ Stored XSS | — | Unknown | < 2.2.93 | 2.2.93 | — | ✓ fixed in latest |
| CVE-2024-9636 | Post Grid and Gutenberg Blocks 2.2.85 - 2.3.3 - Unauthenticated Privilege Escalation | — | Unknown | < 2.3.4 | 2.3.4 | — | ✓ fixed in latest |
| CVE-2025-63043 | Post Grid and Gutenberg Blocks <= 2.3.19 - Unauthenticated Insecure Direct Object Reference | — | Unknown | not specified | no fix on file | — | — |
| CVE-2025-68605 | Post Grid and Gutenberg Blocks <= 2.3.21 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | not specified | no fix on file | — | — |
How to fix it
Keep Post Grid updated — 2.3.24 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
2 of the vulnerabilities above have no fixed version on file — there's no update that resolves them. Consider deactivating this plugin or switching to one of the alternatives below.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Content Views – Post Grid & Filter (Shortcode, Blocks, Elementor Widgets) — 100000+ active installs — 96/100 (333) — max PHP 8.4
- The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid — 100000+ active installs — 96/100 (265) — max PHP 8.4
- Filter Everything — WordPress & WooCommerce Filters — 50000+ active installs — 90/100 (148) — max PHP 8.4
- Post Grid Gutenberg Blocks – PostX — 40000+ active installs — 96/100 (261)
- Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News — 30000+ active installs — 94/100 (79)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.