PT-2025-33997 · WordPress · Gutenberg Blocks+1

Ananda Dhakal

·

Published

2025-08-20

·

Updated

2025-08-20

·

CVE-2025-54007

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: PickPlugins Post Grid and Gutenberg Blocks versions through 2.3.11
Description: Deserialization of untrusted data in PickPlugins Post Grid and Gutenberg Blocks allows for object injection.
Recommendations: Versions prior to 2.3.11 are affected.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-54007

Affected Products

Gutenberg Blocks
Pickplugins Post Grid