Vulnerabilities > Pickplugins

DATE CVE VULNERABILITY TITLE RISK
2024-10-16 CVE-2021-4450 SQL Injection vulnerability in Pickplugins Post Grid
The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
pickplugins CWE-89
8.8
2024-09-18 CVE-2024-44002 Cross-site Scripting vulnerability in Pickplugins Team Showcase
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Reflected XSS.This issue affects Team Showcase: from n/a through 1.22.25.
network
low complexity
pickplugins CWE-79
6.1
2024-09-15 CVE-2024-45459 Cross-site Scripting vulnerability in Pickplugins Product Slider for Woocommerce
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Product Slider for WooCommerce allows Reflected XSS.This issue affects Product Slider for WooCommerce: from n/a through 1.13.50.
network
low complexity
pickplugins CWE-79
6.1
2024-09-11 CVE-2024-8253 Unspecified vulnerability in Pickplugins Post Grid
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90.
network
low complexity
pickplugins
8.8
2024-06-07 CVE-2024-4042 Cross-site Scripting vulnerability in Pickplugins Comboblocks
The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the menu-wrap-item block in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping.
network
low complexity
pickplugins CWE-79
5.4
2024-06-07 CVE-2024-1988 Cross-site Scripting vulnerability in Pickplugins Post Grid
The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute in blocks in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping.
network
low complexity
pickplugins CWE-79
5.4
2024-02-01 CVE-2023-51666 Cross-site Scripting vulnerability in Pickplugins Related Post
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Related Post allows Stored XSS.This issue affects Related Post: from n/a through 2.0.53.
network
low complexity
pickplugins CWE-79
5.4
2024-01-11 CVE-2023-6645 Cross-site Scripting vulnerability in Pickplugins Post Grid Combo
The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.2.64 due to insufficient input sanitization and output escaping.
network
low complexity
pickplugins CWE-79
5.4
2023-11-30 CVE-2023-40211 Unspecified vulnerability in Pickplugins Post Grid Combo
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.
network
low complexity
pickplugins
7.5
2023-02-13 CVE-2023-0166 Unspecified vulnerability in Pickplugins Product Slider for Woocommerce
The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
network
low complexity
pickplugins
5.4