{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awordpressthe_post_grid_and_gutenberg_blocks_comboblocks/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:the_post_grid_and_gutenberg_blocks_comboblocks:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2024-11080"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["The Post Grid and Gutenberg Blocks – ComboBlocks (2.2.32-2.3.1)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","cve","web-application","injection"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Post Grid and Gutenberg Blocks - ComboBlocks plugin for WordPress is affected by a critical vulnerability (CVE-2024-11080) that allows unauthenticated attackers to perform hook injection. The flaw exists within several functions located in the file ~/includes/blocks/form-wrap/function.php. By leveraging this vulnerability, an unauthenticated remote attacker can trigger WordPress hooks, which may result in unauthorized configuration modifications, data exfiltration, or further compromise of the WordPress site. The vulnerability affects plugin versions 2.2.32 through 2.3.1. Defenders should prioritize auditing web server access logs for anomalous POST requests directed at plugin-specific API or form-processing endpoints and upgrade the plugin to a patched version once available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute unauthorized actions within the WordPress environment. This could lead to full site takeover, unauthorized administrative actions, or persistent backdoor installation. As this plugin is widely used for site building and block management, the potential for widespread impact on affected WordPress installations is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit WordPress site inventory to identify instances of 'The Post Grid and Gutenberg Blocks - ComboBlocks' plugin running versions 2.2.32 to 2.3.1.\u003c/li\u003e\n\u003cli\u003ePatch affected WordPress sites by updating to the latest plugin version released after 2.3.1.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for high-frequency or unusual POST requests targeting paths associated with the plugin's form-wrapping functionality.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T09:30:42Z","date_published":"2026-09-05T09:30:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-11080/","summary":"The Post Grid and Gutenberg Blocks - ComboBlocks plugin for WordPress contains an unauthenticated hook injection vulnerability in versions 2.2.32 to 2.3.1 that allows remote attackers to execute arbitrary actions via hook functions.","title":"Unauthenticated Hook Injection in The Post Grid and Gutenberg Blocks Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-11080/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wordpress:the_post_grid_and_gutenberg_blocks_comboblocks:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}