Impact
The Post Grid WordPress plugin, when installed before version 7.9.5, expands the WordPress allowed-HTML list to include iframe, style, and input tags and applies that list to content created by contributors and higher role users. Those tags are stored in the database and rendered on every page, enabling attackers to inject malicious frames, deface the site’s appearance, or spoof form input. The result is a wide-scoped stored XSS vulnerability can compromise user sessions, facilitate phishing, and alter the visual integrity of the site.
Affected Systems
Any WordPress site running the Post Grid plugin with a version older than 7.9.5 is affected. The flaw applies wherever the plugin is active and content is submitted or edited by a contributor, editor, author, or administrator. No specific operating system or server details are required; the vulnerability is purely at the application layer.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability is highly exploitable because it requires only that a user with contributor or higher privileges create or edit grid content. The CVSS score is 3.5, and the EPSS score is not available, which suggests that no publicly disclosed exploit has been observed yet, but the flaw can be triggered trivially by any privileged user. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires no special network or server configuration beyond the normal WordPress environment and Web request handling.
OpenCVE Enrichment