Impact
The vulnerability allows a contributor to inject malicious client‑side scripts when using the WordPress The Post Grid plugin in any version 7.9.5 or earlier. This type of flaw is a classic input validation weakness that can override normal page rendering and potentially steal session data, deface content, or redirect users. The impact is limited to the front‑end, affecting confidentiality and integrity of the content displayed to visitors.
Affected Systems
RadiusTheme’s The Post Grid plugin for WordPress up to and including version 7.9.5. The plugin is distributed through the WordPress repository and used on a variety of sites that rely on it for dynamic content grids.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so current exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require a malicious contributor to submit content that is rendered by the plugin without proper sanitization; no special credentials or elevated privileges are required beyond normal contributor access.
OpenCVE Enrichment