Vulnerabilities > Pickplugins
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-06-07 | CVE-2024-1988 | Cross-site Scripting vulnerability in Pickplugins Post Grid The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute in blocks in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. | 5.4 |
2024-02-01 | CVE-2023-51666 | Cross-site Scripting vulnerability in Pickplugins Related Post Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Related Post allows Stored XSS.This issue affects Related Post: from n/a through 2.0.53. | 5.4 |
2024-01-11 | CVE-2023-6645 | Cross-site Scripting vulnerability in Pickplugins Post Grid Combo The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.2.64 due to insufficient input sanitization and output escaping. | 5.4 |
2023-11-30 | CVE-2023-40211 | Unspecified vulnerability in Pickplugins Post Grid Combo Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50. | 7.5 |
2023-02-13 | CVE-2023-0166 | Unspecified vulnerability in Pickplugins Product Slider for Woocommerce The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | 5.4 |
2023-02-06 | CVE-2022-4836 | Unspecified vulnerability in Pickplugins Breadcrumb The Breadcrumb WordPress plugin before 1.5.33 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | 5.4 |
2023-01-23 | CVE-2022-4693 | Insufficiently Protected Credentials vulnerability in Pickplugins User Verification The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. | 9.8 |
2022-04-11 | CVE-2021-24986 | Unspecified vulnerability in Pickplugins Post Grid The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form | 6.1 |
2022-04-11 | CVE-2022-0447 | Unspecified vulnerability in Pickplugins Post Grid The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting | 6.4 |
2021-08-02 | CVE-2021-24488 | Unspecified vulnerability in Pickplugins Post Grid The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues | 6.1 |