WordPress Plugin Vulnerabilities

The Post Grid < 7.9.5 - Contributor+ Stored HTML/iframe Injection via wp_kses_post Allow-List Widening

Description

The plugin does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input elements that are normally stripped from their content, leading to HTML injection (phishing frames, CSS defacement and spoofed input forms) that renders to any visitor and to administrators reviewing the content.

Proof of Concept

Affects Plugins

Fixed in 7.9.5

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Revanth Hari Narayana Matte
Submitter
Revanth Hari Narayana Matte
Verified
Yes

Timeline

Publicly Published
2026-09-22 (about 2 days ago)
Added
2026-09-22 (about 1 day ago)
Last Updated
2026-09-22 (about 1 day ago)

Other