CVE-2026-84151 Details
Description
The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input elements that are normally stripped from their content, leading to HTML injection (phishing frames, CSS defacement and spoofed input forms) that renders to any visitor and to administrators reviewing the content.
A stored HTML injection vulnerability has been identified in the Post Grid WordPress plugin, affecting versions prior to 7.9.5. The issue arises because the plugin does not restrict the expansion of the WordPress allowed-HTML list to its own markup, applying it site-wide instead. This oversight enables users with the Contributor role and above to include iframe, style, and input elements in their content—elements that are typically removed. As a result, this vulnerability could be exploited to inject HTML that creates phishing frames, defaces content with CSS, or spoof input forms, with the injected HTML being visible to all visitors and to administrators reviewing the content.
Users are advised to update the Post Grid WordPress plugin to version 7.9.5 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026CISA-ADP
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/6601a305-a76f-40fe-8d78-c6a33a66d5f3/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Post Grid | < 7.9.5 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | CVE Modified | CISA-ADP |
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion