PickPlugins records
36 published records for vendor pickplugins.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-862 Missing Authorization2
- CWE-502 Deserialization of Untrusted Data2
- CWE-522 Insufficiently Protected Credentials1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
36 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-4693No exploit | User Verification < 1.0.94 - Authentication Bypasspickplugins · user verification · CWE-522 | Critical9.8 | — | 1.6% | Jan 23, 2023 |
38Monitor | CVE-2024-8253No exploit | Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalationpickplugins · post grid · CWE-266 | High8.8 | — | 9.4% | Sep 11, 2024 |
36Monitor | CVE-2020-35939No exploit | PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to injectpickplugins · post grid · CWE-502 | High8.8 | — | 2.1% | Dec 31, 2020 |
36Monitor | CVE-2020-35938No exploit | PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbipickplugins · post grid · CWE-502 | High8.8 | — | 2.1% | Dec 31, 2020 |
35Monitor | CVE-2024-13408No exploit | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusionpickplugins · post grid · CWE-98 | High8.8 | — | 0.6% | Jan 24, 2025 |
35Monitor | CVE-2021-4450No exploit | Post Grid <= 2.1.12 - Contributor+ SQL Injectionpickplugins · post grid · CWE-89 | High8.8 | — | 0.5% | Oct 16, 2024 |
33Monitor | CVE-2020-35936No exploit | Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers tpickplugins · post grid · CWE-79 | High8.0 | — | 1.7% | Dec 31, 2020 |
33Monitor | CVE-2020-35937No exploit | Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackpickplugins · post grid · CWE-79 | High8.0 | — | 1.7% | Dec 31, 2020 |
31Monitor | CVE-2023-40211Proof of concept | WordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data Exposurepickplugins · post grid combo · CWE-200 | High7.5 | — | 2.2% | Nov 30, 2023 |
30Monitor | CVE-2024-32816No exploit | WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerabilitypickplugins · post grid · CWE-200 | High7.5 | — | 0.7% | Apr 24, 2024 |
30Monitor | CVE-2023-7072No exploit | Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpointpickplugins · post grid combo · CWE-202 | High7.5 | — | 0.6% | Mar 12, 2024 |
30Monitor | CVE-2024-38726No exploit | WordPress Product Designer plugin <= 1.0.33 - Arbitrary Content Deletion vulnerabilitypickplugins · product designer · CWE-862 | High7.5 | — | 0.5% | Nov 1, 2024 |
30Monitor | CVE-2024-13796No exploit | Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposurepickplugins · post grid · CWE-200 | High7.5 | — | 0.4% | Feb 28, 2025 |
27Monitor | CVE-2021-24488Proof of concept | Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)pickplugins · post grid · CWE-79 | Medium6.1 | — | 11.2% | Aug 2, 2021 |
27Monitor | CVE-2021-24300Proof of concept | PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)pickplugins · product slider for woocommerce · CWE-79 | Medium6.1 | — | 10.6% | May 24, 2021 |
26Monitor | CVE-2024-0881Proof of concept | Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Accesspickplugins · post grid · CWE-863 | Medium5.4 | — | 16.9% | Apr 11, 2024 |
25Monitor | CVE-2022-0447No exploit | Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_typespickplugins · post grid · CWE-79 | Medium6.4 | — | 0.6% | Apr 11, 2022 |
25Monitor | CVE-2024-7588No exploit | Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Blockpickplugins · post grid · CWE-79 | Medium6.4 | — | 0.3% | Aug 14, 2024 |
25Monitor | CVE-2024-3155No exploit | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scrpickplugins · post grid · CWE-79 | Medium6.4 | — | 0.3% | May 20, 2024 |
24Monitor | CVE-2021-24986No exploit | Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keywordpickplugins · post grid · CWE-79 | Medium6.1 | — | 0.8% | Apr 11, 2022 |
24Monitor | CVE-2024-45459No exploit | WordPress Product Slider for WooCommerce by PickPlugins plugin <= 1.13.50 - Reflected Cross Site Scripting (XSS) vulnerabilitypickplugins · product slider for woocommerce · CWE-79 | Medium6.1 | — | 0.3% | Sep 15, 2024 |
24Monitor | CVE-2024-44002No exploit | WordPress Team Showcase plugin <= 1.22.25 - Reflected Cross Site Scripting (XSS) vulnerabilitypickplugins · team showcase · CWE-79 | Medium6.1 | — | 0.3% | Sep 17, 2024 |
21Monitor | CVE-2020-13644No exploit | An issue was discovered in the Accordion plugin before 2.2.9 for WordPress.pickplugins · accordion · CWE-79 | Medium5.4 | — | 0.8% | May 28, 2020 |
21Monitor | CVE-2021-24283No exploit | Accordion < 2.2.30 - Authenticated Reflected Cross-Site Scripting (XSS)pickplugins · accordion · CWE-79 | Medium5.4 | — | 0.6% | May 14, 2021 |
21Monitor | CVE-2022-4836No exploit | Breadcrumb < 1.5.33 - Contributor+ Stored XSS via Shortcodepickplugins · breadcrumb · CWE-79 | Medium5.4 | — | 0.6% | Feb 6, 2023 |
- CVE-2022-469339Monitor
User Verification < 1.0.94 - Authentication Bypass
CriticalCVSS 9.8No exploitEPSS 2%pickplugins · user verificationJan 23, 2023
- CVE-2024-825338Monitor
Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation
HighCVSS 8.8No exploitEPSS 9%pickplugins · post gridSep 11, 2024
- CVE-2020-3593936Monitor
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject
HighCVSS 8.8No exploitEPSS 2%pickplugins · post gridDec 31, 2020
- CVE-2020-3593836Monitor
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbi
HighCVSS 8.8No exploitEPSS 2%pickplugins · post gridDec 31, 2020
- CVE-2024-1340835Monitor
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion
HighCVSS 8.8No exploitEPSS 1%pickplugins · post gridJan 24, 2025
- CVE-2021-445035Monitor
Post Grid <= 2.1.12 - Contributor+ SQL Injection
HighCVSS 8.8No exploitEPSS 0%pickplugins · post gridOct 16, 2024
- CVE-2020-3593633Monitor
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers t
HighCVSS 8.0No exploitEPSS 2%pickplugins · post gridDec 31, 2020
- CVE-2020-3593733Monitor
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attack
HighCVSS 8.0No exploitEPSS 2%pickplugins · post gridDec 31, 2020
- CVE-2023-4021131Monitor
WordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data Exposure
HighCVSS 7.5Proof of conceptEPSS 2%pickplugins · post grid comboNov 30, 2023
- CVE-2024-3281630Monitor
WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerability
HighCVSS 7.5No exploitEPSS 1%pickplugins · post gridApr 24, 2024
- CVE-2023-707230Monitor
Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint
HighCVSS 7.5No exploitEPSS 1%pickplugins · post grid comboMar 12, 2024
- CVE-2024-3872630Monitor
WordPress Product Designer plugin <= 1.0.33 - Arbitrary Content Deletion vulnerability
HighCVSS 7.5No exploitEPSS 0%pickplugins · product designerNov 1, 2024
- CVE-2024-1379630Monitor
Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure
HighCVSS 7.5No exploitEPSS 0%pickplugins · post gridFeb 28, 2025
- CVE-2021-2448827Monitor
Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
MediumCVSS 6.1Proof of conceptEPSS 11%pickplugins · post gridAug 2, 2021
- CVE-2021-2430027Monitor
PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)
MediumCVSS 6.1Proof of conceptEPSS 11%pickplugins · product slider for woocommerceMay 24, 2021
- CVE-2024-088126Monitor
Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access
MediumCVSS 5.4Proof of conceptEPSS 17%pickplugins · post gridApr 11, 2024
- CVE-2022-044725Monitor
Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types
MediumCVSS 6.4No exploitEPSS 1%pickplugins · post gridApr 11, 2022
- CVE-2024-758825Monitor
Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block
MediumCVSS 6.4No exploitEPSS 0%pickplugins · post gridAug 14, 2024
- CVE-2024-315525Monitor
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scr
MediumCVSS 6.4No exploitEPSS 0%pickplugins · post gridMay 20, 2024
- CVE-2021-2498624Monitor
Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keyword
MediumCVSS 6.1No exploitEPSS 1%pickplugins · post gridApr 11, 2022
- CVE-2024-4545924Monitor
WordPress Product Slider for WooCommerce by PickPlugins plugin <= 1.13.50 - Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%pickplugins · product slider for woocommerceSep 15, 2024
- CVE-2024-4400224Monitor
WordPress Team Showcase plugin <= 1.22.25 - Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%pickplugins · team showcaseSep 17, 2024
- CVE-2020-1364421Monitor
An issue was discovered in the Accordion plugin before 2.2.9 for WordPress.
MediumCVSS 5.4No exploitEPSS 1%pickplugins · accordionMay 28, 2020
- CVE-2021-2428321Monitor
Accordion < 2.2.30 - Authenticated Reflected Cross-Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 1%pickplugins · accordionMay 14, 2021
- CVE-2022-483621Monitor
Breadcrumb < 1.5.33 - Contributor+ Stored XSS via Shortcode
MediumCVSS 5.4No exploitEPSS 1%pickplugins · breadcrumbFeb 6, 2023