WPIntell

Source evidence

Vulnerabilities in plugin

Post Grid · support · 2026-04-13T06:39:00+00:00

mixedsentiment
highseverity
0.94relevance
4replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 18 rows with source links

27.8% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

13 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
jrrsdu resolved
According to ManageWP and patchstack there’s two vulnerability ( link 1 and link 2 ) in version 2.3.23 and below of Post Grid . Is there a new version of the plugin on the way where the vulnerabilities have been resolved? Any news regarding the vulnerabilities I wrote about a little over a week ago? hi, we do not have access to details issue, we will wait for access to report or they usually send us these issue mail, but last two issue we haven’t received any mail/report, we will wait for wordpress.org report mail to fix the issue. I hope you understand. Regards According to Patchstack, these vulnerabilities were reported in November 2025. https://patchstack.com/database/wordpress/plugin/post-grid/vulnerability/wordpress-post-grid-and-gutenberg-blocks-plugin-2-3-18-cross-site-scripting-xss-vulnerability https://patchstack.com/database/wordpress/plugin/post-grid/vulnerability/wordpress-post-grid-and-gutenberg-blocks-plugin-2-3-19-insecure-direct-object-references-idor-vulnerability We have checked the issue and found these issues was related to blocks, all blocks move to our new plugin combo-blocks plugin we have submitted patched report to wordfence, i hope they will approve.

Comments

4 shown
jrrsdu 2026-04-23T13:17:00+00:00

Any news regarding the vulnerabilities I wrote about a little over a week ago?

hasanrang05 2026-04-28T04:19:00+00:00

hi, we do not have access to details issue, we will wait for access to report or they usually send us these issue mail, but last two issue we haven’t received any mail/report, we will wait for wordpress.org report mail to fix the issue. I hope you understand. Regards

tofraser 2026-04-29T18:49:00+00:00

According to Patchstack, these vulnerabilities were reported in November 2025. https://patchstack.com/database/wordpress/plugin/post-grid/vulnerability/wordpress-post-grid-and-gutenberg-blocks-plugin-2-3-18-cross-site-scripting-xss-vulnerability https://patchstack.com/database/wordpress/plugin/post-grid/vulnerability/wordpress-post-grid-and-gutenberg-blocks-plugin-2-3-19-insecure-direct-object-references-idor-vulnerability

hasanrang05 2026-04-30T07:41:00+00:00

We have checked the issue and found these issues was related to blocks, all blocks move to our new plugin combo-blocks plugin we have submitted patched report to wordfence, i hope they will approve.