View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Critical hook injection in Post Grid ComboBlocks WordPress plugin

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Critical unauthenticated hook injection in Post Grid ComboBlocks WordPress plugin (CVE-2024-11080)
    The Post Grid and Gutenberg Blocks โ€“ ComboBlocks WordPress plugin is vulnerable to unauthenticated hook injection in versions 2.2.32 to 2.3.1.

    • Affects WordPress sites running the Post Grid and Gutenberg Blocks โ€“ ComboBlocks plugin by pickplugins, versions 2.2.32 to 2.3.1 (2.2.85 listed as affected).
    • The flaw, tracked as CVE-2024-11080 (CWE-94 code injection), is rated critical with a CVSS 3.1 score of 9.8.
    • Several functions in ~/includes/blocks/form-wrap/function.php allow unauthenticated attackers to execute actions with WordPress hooks, provided no other security controls are present.
    • The vulnerability was found by Chloe Chamberland and assigned by Wordfence; the vendor was notified in September 2026.
    • No CVE-based attack activity is reported in the material; the issue is a network-exploitable bug requiring no privileges or user interaction.
      ๐Ÿ“„ Source: wordfence.com ยท ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel โ€” The Hacker News

  • Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities โ€” The Hacker News

  • Abandoned Cart Pro for WooCommerce through 10.7.1 - Missing Authorization to Authe... โ€” CVE ThreatInt

  • Contact Form by Supsystic through 1.10.2 - Unauthenticated Stored Cross-Site Scrip... โ€” CVE ThreatInt

  • Custom Contact Forms through 7.16 - Missing Authorization to Authenticated (Contri... โ€” CVE ThreatInt

  • Unlimited Elements For Elementor through 2.0.17 - Reflected Cross-Site Scripting v... โ€” CVE ThreatInt

  • Microsoft Teams Desktop Client Fails to Load on Windows System โ€“ Microsoft Investigating โ€” Cyber Security News

  • AI Agents Breach Company Network in Under 10 Hours and Steal Root Credentials โ€” Cyber Security News

  • Ignition Gateway Authenticated Project Creation Bypass (CVE-2026-77393) โ€” thehackerwire.com (discovered)

  • Million-dollar phishing campaign uses invisible Unicode characters to bypass email filters โ€” r/netsec

  • Detecting and simulating password spraying against Entra ID โ€” securityboulevard.com (discovered)

  • The New AI Inference Stack: From Faster Kernels to Inference Economics โ€” securityboulevard.com (discovered)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check