CVE-2023-7072: Pickplugins Post Grid Combo

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 via the 'get_posts' REST API Endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including full draft posts and password protected posts, as well as the password for password-protected posts.

Affected products

  • Pickplugins Post Grid Combo: before 2.2.69 (fixed in 2.2.69)

Published 2024-03-12. Last modified 2026-06-17.