Skip to content
Noroxi

PickPlugins records

36 published records for vendor pickplugins.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
25%
Median publish → KEV
No record has entered KEV

All records

36 records
  • CVE-2022-4693
    39Monitor

    User Verification < 1.0.94 - Authentication Bypass

    CriticalCVSS 9.8No exploitEPSS 2%

    pickplugins · user verificationJan 23, 2023

  • CVE-2024-8253
    38Monitor

    Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation

    HighCVSS 8.8No exploitEPSS 9%

    pickplugins · post gridSep 11, 2024

  • PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject

    HighCVSS 8.8No exploitEPSS 2%

    pickplugins · post gridDec 31, 2020

  • PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbi

    HighCVSS 8.8No exploitEPSS 2%

    pickplugins · post gridDec 31, 2020

  • Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion

    HighCVSS 8.8No exploitEPSS 1%

    pickplugins · post gridJan 24, 2025

  • CVE-2021-4450
    35Monitor

    Post Grid <= 2.1.12 - Contributor+ SQL Injection

    HighCVSS 8.8No exploitEPSS 0%

    pickplugins · post gridOct 16, 2024

  • Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers t

    HighCVSS 8.0No exploitEPSS 2%

    pickplugins · post gridDec 31, 2020

  • Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attack

    HighCVSS 8.0No exploitEPSS 2%

    pickplugins · post gridDec 31, 2020

  • WordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data Exposure

    HighCVSS 7.5Proof of conceptEPSS 2%

    pickplugins · post grid comboNov 30, 2023

  • WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    pickplugins · post gridApr 24, 2024

  • CVE-2023-7072
    30Monitor

    Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint

    HighCVSS 7.5No exploitEPSS 1%

    pickplugins · post grid comboMar 12, 2024

  • WordPress Product Designer plugin <= 1.0.33 - Arbitrary Content Deletion vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    pickplugins · product designerNov 1, 2024

  • Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure

    HighCVSS 7.5No exploitEPSS 0%

    pickplugins · post gridFeb 28, 2025

  • Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)

    MediumCVSS 6.1Proof of conceptEPSS 11%

    pickplugins · post gridAug 2, 2021

  • PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)

    MediumCVSS 6.1Proof of conceptEPSS 11%

    pickplugins · product slider for woocommerceMay 24, 2021

  • CVE-2024-0881
    26Monitor

    Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access

    MediumCVSS 5.4Proof of conceptEPSS 17%

    pickplugins · post gridApr 11, 2024

  • CVE-2022-0447
    25Monitor

    Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types

    MediumCVSS 6.4No exploitEPSS 1%

    pickplugins · post gridApr 11, 2022

  • CVE-2024-7588
    25Monitor

    Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block

    MediumCVSS 6.4No exploitEPSS 0%

    pickplugins · post gridAug 14, 2024

  • CVE-2024-3155
    25Monitor

    Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scr

    MediumCVSS 6.4No exploitEPSS 0%

    pickplugins · post gridMay 20, 2024

  • Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keyword

    MediumCVSS 6.1No exploitEPSS 1%

    pickplugins · post gridApr 11, 2022

  • WordPress Product Slider for WooCommerce by PickPlugins plugin <= 1.13.50 - Reflected Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    pickplugins · product slider for woocommerceSep 15, 2024

  • WordPress Team Showcase plugin <= 1.22.25 - Reflected Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    pickplugins · team showcaseSep 17, 2024

  • An issue was discovered in the Accordion plugin before 2.2.9 for WordPress.

    MediumCVSS 5.4No exploitEPSS 1%

    pickplugins · accordionMay 28, 2020

  • Accordion < 2.2.30 - Authenticated Reflected Cross-Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 1%

    pickplugins · accordionMay 14, 2021

  • CVE-2022-4836
    21Monitor

    Breadcrumb < 1.5.33 - Contributor+ Stored XSS via Shortcode

    MediumCVSS 5.4No exploitEPSS 1%

    pickplugins · breadcrumbFeb 6, 2023