<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>The Post Grid and Gutenberg Blocks – ComboBlocks (2.2.32-2.3.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/the-post-grid-and-gutenberg-blocks--comboblocks-2.2.32-2.3.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 05 Sep 2026 09:30:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/the-post-grid-and-gutenberg-blocks--comboblocks-2.2.32-2.3.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Hook Injection in The Post Grid and Gutenberg Blocks Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2024-11080/</link><pubDate>Sat, 05 Sep 2026 09:30:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2024-11080/</guid><description>The Post Grid and Gutenberg Blocks - ComboBlocks plugin for WordPress contains an unauthenticated hook injection vulnerability in versions 2.2.32 to 2.3.1 that allows remote attackers to execute arbitrary actions via hook functions.</description><content:encoded><![CDATA[<p>The Post Grid and Gutenberg Blocks - ComboBlocks plugin for WordPress is affected by a critical vulnerability (CVE-2024-11080) that allows unauthenticated attackers to perform hook injection. The flaw exists within several functions located in the file ~/includes/blocks/form-wrap/function.php. By leveraging this vulnerability, an unauthenticated remote attacker can trigger WordPress hooks, which may result in unauthorized configuration modifications, data exfiltration, or further compromise of the WordPress site. The vulnerability affects plugin versions 2.2.32 through 2.3.1. Defenders should prioritize auditing web server access logs for anomalous POST requests directed at plugin-specific API or form-processing endpoints and upgrade the plugin to a patched version once available.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute unauthorized actions within the WordPress environment. This could lead to full site takeover, unauthorized administrative actions, or persistent backdoor installation. As this plugin is widely used for site building and block management, the potential for widespread impact on affected WordPress installations is high.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Audit WordPress site inventory to identify instances of 'The Post Grid and Gutenberg Blocks - ComboBlocks' plugin running versions 2.2.32 to 2.3.1.</li>
<li>Patch affected WordPress sites by updating to the latest plugin version released after 2.3.1.</li>
<li>Monitor web server logs for high-frequency or unusual POST requests targeting paths associated with the plugin's form-wrapping functionality.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>cve</category><category>web-application</category><category>injection</category></item></channel></rss>