HTML Injection Vulnerability in Post Grid WordPress Plugin by WordPress
CVE-2026-84151

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-84151?

The Post Grid WordPress plugin versions prior to 7.9.5 suffer from an HTML injection vulnerability due to inadequate restrictions on the allowed HTML elements. This flaw permits users with Contributor roles and higher to insert iframe, style, and input elements that are typically removed from content. As a result, an attacker could exploit this vulnerability to inject malicious HTML, enabling phishing attacks, CSS defacement, and the creation of spoofed input forms that appear legitimate to both site visitors and administrators. It is crucial for users of the affected versions to update to the latest release to mitigate potential security risks.

Affected Version(s)

The Post Grid 0 < 7.9.5

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Revanth Hari Narayana Matte
WPScan
.