PLUGIN SECURITY

Is Post Grid safe?

Post Grid is a powerful WordPress plugin for creating customizable post grid layouts with advanced query options, allowing users to display posts dyna …

What this plugin does

  • Slug: post-grid
  • Author: PickPlugins
  • 30000+ active installs
  • 86/100 rating (163 reviews on wordpress.org)
  • 3477441 all-time downloads
  • On WordPress.org since 2015-02-06

post filterpost gridPost Masonryposts carouselposts slider

Maintenance status

  • Latest known version: 2.3.24
  • Last updated: 2026-07-19 3:09am GMT
  • Tested up to WordPress: 7.0.4

Known vulnerabilities

32 known CVEs on file for Post Grid.

CVE Vulnerability Type Severity Affected Fixed in Published Status
Post Grid [post-grid] <= 2.3.23 (unfixed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.3.23 2.3.23 2025-12-21 ✓ fixed in latest
Post Grid [post-grid] <= 2.3.23 (unfixed) Authorization Bypass Through User-Controlled Key Unknown < 2.3.23 2.3.23 2025-12-03 ✓ fixed in latest
CVE-2025-62924 Post Grid [post-grid] < 2.3.18 Missing Authorization High 8.8 < 2.3.18 2.3.18 2025-10-04 ✓ fixed in latest
CVE-2025-66058 Post Grid [post-grid] < 2.3.18 Missing Authorization Unknown < 2.3.18 2.3.18 2025-10-04 ✓ fixed in latest
CVE-2025-54007 Post Grid [post-grid] < 2.3.12 Deserialization of Untrusted Data High 8.8 < 2.3.12 2.3.12 2025-08-06 ✓ fixed in latest
CVE-2024-13796 Post Grid [post-grid] < 2.3.7 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 2.3.7 2.3.7 2025-02-27 ✓ fixed in latest
CVE-2024-13798 Post Grid [post-grid] < 2.3.6 Improper Input Validation Medium 5.3 < 2.3.6 2.3.6 2025-02-21 ✓ fixed in latest
CVE-2024-50432 Post Grid [post-grid] < 2.2.94 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.2.94 2.2.94 2024-10-24 ✓ fixed in latest
+ 37 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-47340 Post Grid [post-grid] < 2.2.90 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.2.90 2.2.90 2024-09-27 ✓ fixed in latest
CVE-2024-8253 Post Grid [post-grid] < 2.2.91 Incorrect Privilege Assignment High 8.8 < 2.2.91 2.2.91 2024-09-10 ✓ fixed in latest
CVE-2024-7588 Post Grid [post-grid] < 2.2.88 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.2.88 2.2.88 2024-08-13 ✓ fixed in latest
CVE-2024-43155 Post Grid [post-grid] < 2.2.87 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.2.87 2.2.87 2024-08-07 ✓ fixed in latest
CVE-2024-6346 Post Grid [post-grid] < 2.2.86 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.2.86 2.2.86 2024-07-31 ✓ fixed in latest
CVE-2024-4042 Post Grid [post-grid] < 2.2.81 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.2.81 2.2.81 2024-06-06 ✓ fixed in latest
CVE-2024-1988 Post Grid [post-grid] < 2.2.81 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.2.81 2.2.81 2024-06-06 ✓ fixed in latest
CVE-2024-3155 Post Grid [post-grid] < 2.2.81 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Medium 6.4 < 2.2.81 2.2.81 2024-05-20 ✓ fixed in latest
CVE-2024-32816 Post Grid [post-grid] < 2.2.79 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 2.2.79 2.2.79 2024-04-22 ✓ fixed in latest
CVE-2024-30441 Post Grid [post-grid] < 2.2.76 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 2.2.76 2.2.76 2024-03-28 ✓ fixed in latest
CVE-2024-0881 Post Grid [post-grid] < 2.2.76 Incorrect Authorization Medium 5.4 < 2.2.76 2.2.76 2024-03-19 ✓ fixed in latest
CVE-2023-7072 Post Grid [post-grid] < 2.2.69 Exposure of Sensitive Information Through Data Queries High 7.5 < 2.2.69 2.2.69 2024-03-12 ✓ fixed in latest
CVE-2023-6645 Post Grid [post-grid] < 2.2.65 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.2.65 2.2.65 2023-12-15 ✓ fixed in latest
CVE-2023-40211 Post Grid [post-grid] < 2.2.51 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 2.2.51 2.2.51 2023-08-11 ✓ fixed in latest
CVE-2022-0447 Post Grid [post-grid] < 2.1.16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.1.16 2.1.16 2022-03-15 ✓ fixed in latest
CVE-2021-24986 Post Grid [post-grid] < 2.1.16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.1.16 2.1.16 2022-03-15 ✓ fixed in latest
CVE-2021-4450 Post Grid [post-grid] < 2.1.13 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 2.1.13 2.1.13 2021-12-15 ✓ fixed in latest
CVE-2021-24488 Post Grid [post-grid] < 2.1.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.1.8 2.1.8 2021-06-28 ✓ fixed in latest
CVE-2020-35938, CVE-2020-35939 Post Grid [post-grid] < 2.0.73 Deserialization of Untrusted Data High 8.8 < 2.0.73 2.0.73 2021-01-01 ✓ fixed in latest
CVE-2020-35936, CVE-2020-35937 Post Grid [post-grid] < 2.0.73 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 8.0 < 2.0.73 2.0.73 2021-01-01 ✓ fixed in latest
CVE-2020-35937 Post Grid [post-grid] < 2.0.73 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 8.0 < 2.0.73 2.0.73 2021-01-01 ✓ fixed in latest
CVE-2020-35939 Post Grid [post-grid] < 2.0.73 Deserialization of Untrusted Data High 8.8 < 2.0.73 2.0.73 2021-01-01 ✓ fixed in latest
Post Grid [post-grid] < 2.0.73 Unknown < 2.0.73 2.0.73 2020-10-05 ✓ fixed in latest
Post Grid [post-grid] < 2.0.73 Unknown < 2.0.73 2.0.73 2020-10-05 ✓ fixed in latest
Post Grid [post-grid] < 2.0.13 Unknown < 2.0.13 2.0.13 2016-11-08 ✓ fixed in latest
Post Grid [post-grid] < 2.0.13 Unknown < 2.0.13 2.0.13 2016-11-08 ✓ fixed in latest
Post Grid [post-grid] < 2.0.13 Unknown < 2.0.13 2.0.13 2016-11-08 ✓ fixed in latest
Post Grid [post-grid] >= 2.2.85 - < 2.3.4 Improper Privilege Management Critical 9.8 2.2.85–2.3.4 2.3.4 0000-00-00 ✓ fixed in latest
Post Grid [post-grid] < 2.2.93 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.2.93 2.2.93 0000-00-00 ✓ fixed in latest
Post Grid [post-grid] < 2.1.13 Unknown < 2.1.13 2.1.13 ✓ fixed in latest
Post Grid [post-grid] < 2.0.13 Unknown < 2.0.13 2.0.13 ✓ fixed in latest
Post Grid <= 2.0.12 - Unauthenticated Arbitrary File Deletion Unknown < 2.0.13 2.0.13 ✓ fixed in latest
Post Grid < 2.1.13 - Contributor+ SQL Injection Unknown < 2.1.13 2.1.13 ✓ fixed in latest
CVE-2024-9645 Post Grid and Gutenberg Blocks < 2.2.93 - Contributor+ Stored XSS Unknown < 2.2.93 2.2.93 ✓ fixed in latest
CVE-2024-9636 Post Grid and Gutenberg Blocks 2.2.85 - 2.3.3 - Unauthenticated Privilege Escalation Unknown < 2.3.4 2.3.4 ✓ fixed in latest
CVE-2025-63043 Post Grid and Gutenberg Blocks <= 2.3.19 - Unauthenticated Insecure Direct Object Reference Unknown not specified no fix on file
CVE-2025-68605 Post Grid and Gutenberg Blocks <= 2.3.21 - Authenticated (Contributor+) Stored Cross-Site Scripting Unknown not specified no fix on file

How to fix it

Keep Post Grid updated — 2.3.24 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

2 of the vulnerabilities above have no fixed version on file — there's no update that resolves them. Consider deactivating this plugin or switching to one of the alternatives below.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.