HTML Injection Vulnerability in Post Grid WordPress Plugin by WordPress
CVE-2026-84151
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 24 September 2026
Badges
What is CVE-2026-84151?
The Post Grid WordPress plugin versions prior to 7.9.5 suffer from an HTML injection vulnerability due to inadequate restrictions on the allowed HTML elements. This flaw permits users with Contributor roles and higher to insert iframe, style, and input elements that are typically removed from content. As a result, an attacker could exploit this vulnerability to inject malicious HTML, enabling phishing attacks, CSS defacement, and the creation of spoofed input forms that appear legitimate to both site visitors and administrators. It is crucial for users of the affected versions to update to the latest release to mitigate potential security risks.
Affected Version(s)
The Post Grid 0 < 7.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.