CRITICAL
9.8 CVE-2024-11080 Published 5 Sept 2026
WordPress ComboBlocks Plugin Unauthenticated Hook Injection
Worried this affects one of your servers?
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1.
This is due to several functions in the ~/includes/blocks/form-wrap/function.php file, allowing unauthenticated attackers to execute actions with hooks in WordPress, provided no other security controls are present in the function.
Reference: CVE-2024-11080 on NVD
← Back to Security News