The Post Grid and Gutenberg Blocks (ComboBlocks) plugin for WordPress contains an unauthenticated hook injection vulnerability affecting versions 2.2.32 through 2.3.1. The vulnerability exists in several functions within the ~/includes/blocks/form-wrap/function.php file. Unauthenticated attackers can exploit this flaw to execute arbitrary WordPress actions via hook injection. No authentication is required to trigger the vulnerability, making it accessible to any remote attacker. The risk is contingent on the absence of additional security controls within the affected functions. The vulnerability has been documented by Wordfence and published in the NVD. Site administrators using affected versions should update the plugin immediately to mitigate potential exploitation.