CVE-2026-94680: WordPress The Post Grid plugin <= 7.9.5 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress The Post Grid pluginto a version that resolves this vulnerability.Fixed in 7.9.6
Event History
Frequently Asked Questions
What level of access does an attacker need?
The attacker needs low-level authenticated access, identified as contributor access. The attack is network-accessible and has low attack complexity once that access is available.
Does exploitation require another user to do anything?
Yes. The CVSS vector indicates user interaction is required, meaning a user must interact with the attacker-controlled content for the XSS to execute.
Which sites should be prioritized for review?
Prioritize sites running The Post Grid version 7.9.5 or earlier that allow contributor-level accounts. Sites without contributor access have a reduced exposure to the stated attack prerequisite.
How can I determine whether my site is potentially affected?
Check the installed The Post Grid version and review whether it is 7.9.5 or earlier. Also review existing contributor accounts, since contributor-level privileges are required for exploitation.