CVE-2024-11080
⛔ criticalSummary
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress, granted no other security controls are present in the function.
CVSS Score
9.8
Critical
EPSS Score
0.4
Exploit Probability
Published Date
2026-09-05
First Seen: 2026-09-06
📊 Relative Risk Intelligence
This CVE is Very High Risk - more severe than 90.5% of all 353,175 vulnerabilities in our database.
#33,631
Top 10% most severe
Severity Percentile
Last Modified
2026-09-05
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)