Vulnerabilities > Wpwax > Post Grid Slider Carousel Ultimate > 1.4.0

DATE CVE VULNERABILITY TITLE RISK
2025-01-27 CVE-2025-24782 PHP Remote File Inclusion vulnerability in Wpwax Post Grid, Slider & Carousel Ultimate
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Post Grid, Slider & Carousel Ultimate allows PHP Local File Inclusion.
network
low complexity
wpwax CWE-98
8.8
2025-01-24 CVE-2024-13409 Unspecified vulnerability in Wpwax Post Grid, Slider & Carousel Ultimate
The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 via the 'theme' parameter of the post_type_ajax_handler() function.
network
low complexity
wpwax
8.8
2024-03-27 CVE-2024-29925 Unspecified vulnerability in Wpwax Post Grid, Slider & Carousel Ultimate
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Post Grid, Slider & Carousel Ultimate allows Stored XSS.This issue affects Post Grid, Slider & Carousel Ultimate: from n/a through 1.6.6.
network
low complexity
wpwax
5.4
2022-06-20 CVE-2022-1266 Unspecified vulnerability in Wpwax Post Grid, Slider & Carousel Ultimate
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
network
low complexity
wpwax
4.8