CRITICAL 9.8 CVE-2024-11080 Published 5 Sept 2026

WordPress ComboBlocks Plugin Unauthenticated Hook Injection

Worried this affects one of your servers?

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1.

This is due to several functions in the ~/includes/blocks/form-wrap/function.php file, allowing unauthenticated attackers to execute actions with hooks in WordPress, provided no other security controls are present in the function.

Reference: CVE-2024-11080 on NVD

← Back to Security News