Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Post Grid MEDIUM 5.4
CVE-2024-9645

The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate and escape some of its block …

Fix: 2.2.93+
Fix from $1,600 2025-05-15
Pricing Table MEDIUM 5.4
CVE-2024-13469

The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link in all versions up to, and inc…

Fix: after 1.12.10
Fix from $1,600 2025-02-28
Post Grid HIGH 7.5
CVE-2024-13796

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl…

Fix: 2.3.7+
Fix from $1,950 2025-02-28
Comboblocks MEDIUM 5.3
CVE-2024-13798

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and includi…

Fix: 2.3.6+
Fix from $1,600 2025-02-22
Post Grid HIGH 8.8
CVE-2024-13408

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclu…

Fix: 1.7+
Fix from $1,950 2025-01-24
Post Grid HIGH 8.8
CVE-2021-4450

The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficien…

Fix: after 2.1.12
Fix from $1,950 2024-10-16
Team Showcase MEDIUM 6.1
CVE-2024-44002

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase team allows Reflected…

Fix: after 1.22.25
Fix from $1,600 2024-09-18
Product Slider For Woocommerce MEDIUM 6.1
CVE-2024-45459

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Product Slider for WooCommerce wooc…

Fix: 1.13.51+
Fix from $1,600 2024-09-15
Post Grid HIGH 8.8
CVE-2024-8253EPSS 9%

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the pl…

Fix: 2.2.91+
Fix from $1,950 2024-09-11
Comboblocks MEDIUM 5.4
CVE-2024-6346

The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the redirectURL parameter of t…

Fix: 2.2.86+
Fix from $1,600 2024-08-01
Comboblocks MEDIUM 5.4
CVE-2024-4042

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cr…

Fix: 2.2.81+
Fix from $1,600 2024-06-07
Post Grid MEDIUM 5.4
CVE-2024-1988

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cr…

Fix: 2.2.81+
Fix from $1,600 2024-06-07
Post Grid MEDIUM 5.4
CVE-2024-0881EPSS 17%

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authoriza…

Fix: 2.2.76+
Fix from $1,600 2024-04-11
Post Grid Combo HIGH 7.5
CVE-2023-7072

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,…

Fix: 2.2.69+
Fix from $1,950 2024-03-12
Related Post MEDIUM 5.4
CVE-2023-51666

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Related Post allows Stored XSS.This…

Fix: after 2.0.53
Fix from $1,600 2024-02-01
Post Grid Combo MEDIUM 5.4
CVE-2023-6645

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versi…

Fix: after 2.2.64
Fix from $1,600 2024-01-11
Post Grid Combo HIGH 7.5
CVE-2023-40211

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Pos…

Fix: 2.2.51+
Fix from $1,950 2023-11-30
Product Slider For Woocommerce MEDIUM 5.4
CVE-2023-0166

The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes befor…

Fix: 1.13.42+
Fix from $1,600 2023-02-13
Breadcrumb MEDIUM 5.4
CVE-2022-4836

The Breadcrumb WordPress plugin before 1.5.33 does not validate and escape some of its shortcode attributes before outputting them back in the page, …

Fix: 1.5.33+
Fix from $1,600 2023-02-06
User Verification CRITICAL 9.8
CVE-2022-4693

The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to…

Fix: 1.0.94+
Fix from $2,300 2023-01-23
Post Grid MEDIUM 6.4
CVE-2022-0447

The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the p…

Fix: 2.1.16+
Fix from $1,600 2022-04-11
Post Grid MEDIUM 6.1
CVE-2021-24986

The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected …

Fix: 2.1.16+
Fix from $1,600 2022-04-11
Post Grid MEDIUM 6.1
CVE-2021-24488EPSS 11%

The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being ou…

Fix: 2.1.8+
Fix from $1,600 2021-08-02
Product Slider For Woocommerce MEDIUM 6.1
CVE-2021-24300EPSS 11%

The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the key…

Fix: 1.13.22+
Fix from $1,600 2021-05-24
Accordion MEDIUM 5.4
CVE-2021-24283

The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, leading to a reflected XSS issue.

Fix: 2.2.30+
Fix from $1,600 2021-05-14
Post Grid HIGH 8.8
CVE-2020-35938

PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP…

Fix: 1.22.16 / 2.0.73+
Fix from $1,950 2021-01-01
Post Grid HIGH 8.8
CVE-2020-35939

PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrar…

Fix: 1.22.16 / 2.0.73+
Fix from $1,950 2021-01-01
Post Grid HIGH 8.0
CVE-2020-35936

Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import …

Fix: 1.22.16 / 2.0.73+
Fix from $1,950 2021-01-01
Post Grid HIGH 8.0
CVE-2020-35937

Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to im…

Fix: 1.22.16 / 2.0.73+
Fix from $1,950 2021-01-01
Accordion MEDIUM 5.4
CVE-2020-13644

An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed a…

Fix: 2.2.9+
Fix from $1,600 2020-05-28