Vulnerabilities > Pickplugins > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-18 | CVE-2024-44002 | Cross-site Scripting vulnerability in Pickplugins Team Showcase Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Reflected XSS.This issue affects Team Showcase: from n/a through 1.22.25. | 6.1 |
2024-09-15 | CVE-2024-45459 | Cross-site Scripting vulnerability in Pickplugins Product Slider for Woocommerce Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Product Slider for WooCommerce allows Reflected XSS.This issue affects Product Slider for WooCommerce: from n/a through 1.13.50. | 6.1 |
2024-06-07 | CVE-2024-4042 | Cross-site Scripting vulnerability in Pickplugins Comboblocks The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the menu-wrap-item block in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. | 5.4 |
2024-06-07 | CVE-2024-1988 | Cross-site Scripting vulnerability in Pickplugins Post Grid The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute in blocks in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. | 5.4 |
2024-02-01 | CVE-2023-51666 | Cross-site Scripting vulnerability in Pickplugins Related Post Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Related Post allows Stored XSS.This issue affects Related Post: from n/a through 2.0.53. | 5.4 |
2024-01-11 | CVE-2023-6645 | Cross-site Scripting vulnerability in Pickplugins Post Grid Combo The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.2.64 due to insufficient input sanitization and output escaping. | 5.4 |
2023-02-13 | CVE-2023-0166 | Unspecified vulnerability in Pickplugins Product Slider for Woocommerce The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | 5.4 |
2023-02-06 | CVE-2022-4836 | Unspecified vulnerability in Pickplugins Breadcrumb The Breadcrumb WordPress plugin before 1.5.33 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | 5.4 |
2022-04-11 | CVE-2021-24986 | Unspecified vulnerability in Pickplugins Post Grid The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form | 6.1 |
2022-04-11 | CVE-2022-0447 | Unspecified vulnerability in Pickplugins Post Grid The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting | 6.4 |