---
id: CVE-2026-84151
title: >-
  The Post Grid  WordPress plugin before 7.9.5 does not limit an expansion of
  the WordPress allowed-HTML list to its own markup and applies it site-wide,
  allowing users with the Contributor role and above to store iframe, style and
  input e…
summary: >-
  The Post Grid  WordPress plugin before 7.9.5 does not limit an expansion of
  the WordPress allowed-HTML list to its own markup and applies it site-wide,
  allowing users with the Contributor role and above to store iframe, style and
  input e…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-79
product: The Post Grid
affected:
  - the_post_grid < 7.9.5
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:42:02.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84151'
references:
  - url: 'https://wpscan.com/vulnerability/6601a305-a76f-40fe-8d78-c6a33a66d5f3/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T10:35:16.466485Z'
ingestedAt: '2026-09-24T06:39:26.613Z'
---

## Overview

The Post Grid  WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input elements that are normally stripped from their content, leading to HTML injection (phishing frames, CSS defacement and spoofed input forms) that renders to any visitor and to administrators reviewing the content.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
