Vulnerabilities > Pickplugins

DATE CVE VULNERABILITY TITLE RISK
2024-02-01 CVE-2023-51666 Cross-site Scripting vulnerability in Pickplugins Related Post
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Related Post allows Stored XSS.This issue affects Related Post: from n/a through 2.0.53.
network
low complexity
pickplugins CWE-79
5.4
2024-01-11 CVE-2023-6645 Cross-site Scripting vulnerability in Pickplugins Post Grid Combo
The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.2.64 due to insufficient input sanitization and output escaping.
network
low complexity
pickplugins CWE-79
5.4
2023-11-30 CVE-2023-40211 Unspecified vulnerability in Pickplugins Post Grid Combo
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.
network
low complexity
pickplugins
7.5
2023-02-13 CVE-2023-0166 Unspecified vulnerability in Pickplugins Product Slider for Woocommerce
The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
network
low complexity
pickplugins
5.4
2023-02-06 CVE-2022-4836 Unspecified vulnerability in Pickplugins Breadcrumb
The Breadcrumb WordPress plugin before 1.5.33 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
network
low complexity
pickplugins
5.4
2023-01-23 CVE-2022-4693 Insufficiently Protected Credentials vulnerability in Pickplugins User Verification
The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability.
network
low complexity
pickplugins CWE-522
critical
9.8
2022-04-11 CVE-2021-24986 Cross-site Scripting vulnerability in Pickplugins Post Grid
The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form
4.3
2022-04-11 CVE-2022-0447 Cross-site Scripting vulnerability in Pickplugins Post Grid
The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting
3.5
2021-08-02 CVE-2021-24488 Cross-site Scripting vulnerability in Pickplugins Post Grid
The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues
4.3
2021-05-24 CVE-2021-24300 Cross-site Scripting vulnerability in Pickplugins Product Slider for Woocommerce
The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue
4.3