CVE-2025-54007: WordPress Post Grid and Gutenberg Blocks Plugin <= 2.3.11 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Object Injection. This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.3.11.
Other sources
Deserialization of Untrusted Data vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Object Injection.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.11.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54007?
The severity of CVE-2025-54007 is considered high due to the potential for object injection attacks.
How do I fix CVE-2025-54007?
To fix CVE-2025-54007, update the PickPlugins Post Grid and Gutenberg Blocks plugin to version 2.3.12 or later.
What type of vulnerability is CVE-2025-54007?
CVE-2025-54007 is a deserialization of untrusted data vulnerability that allows for object injection.
Which versions of the plugin are affected by CVE-2025-54007?
CVE-2025-54007 affects versions from n/a up to and including 2.3.11 of the PickPlugins Post Grid and Gutenberg Blocks.
Who is impacted by CVE-2025-54007?
Users of the PickPlugins Post Grid and Gutenberg Blocks plugin prior to version 2.3.12 are at risk from CVE-2025-54007.