Impact
A contributor Cross Site Scripting vulnerability exists in the WordPress The Post Grid plugin versions 7.9.5 and earlier, allowing an attacker to inject malicious script content that will be rendered in the browser context. The flaw arises from insufficient sanitization of user‑supplied input, which means that any script inserted by a contributor can potentially execute in the context of other site visitors. This can lead to defacement, credential theft, or further exploitation of the site. The weakness is identified as CWE‑79, indicating an XSS flaw caused by improper neutralization of user input.
Affected Systems
The vulnerability affects WordPress installations that use the RadiusTheme The Post Grid plugin, version 7.9.5 or older. Sites that have not yet upgraded this plugin are at risk. No other WordPress core components or third‑party plugins are specifically mentioned as affected.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity; there is no EPSS score available, and the issue is not listed in CISA’s KEV catalog. The likely attack vector involves a contributor or user creating content that contains injected script, which is then rendered by the plugin in the frontend. Based on the description, the vulnerability can be leveraged by anyone who can supply content to the plugin, which may include any logged‑in contributor with appropriate permissions. The risk is therefore notable for sites where contributor access is broader than necessary.
OpenCVE Enrichment