CVE-2024-11080 PUBLISHED

Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection

Assigner: Wordfence
Reserved: 11.11.2024 Published: 05.09.2026 Updated: 05.09.2026

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress, granted no other security controls are present in the function.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor pickplugins
Product Post Grid
Versions Default: unaffected
  • affected from 2.2.85 to 2.3.32 (incl.)

Credits

  • Chloe Chamberland finder

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE