Записи PickPlugins
36 опубликованных записей вендора pickplugins.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 25 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-862 Missing Authorization2
- CWE-502 Deserialization of Untrusted Data2
- CWE-522 Insufficiently Protected Credentials1
- CWE-863 Incorrect Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
36 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2022-4693Эксплойта нет | User Verification < 1.0.94 - Authentication Bypasspickplugins · user verification · CWE-522 | Критическая9,8 | — | 1,6 % | 23 янв. 2023 г. |
38Наблюдать | CVE-2024-8253Эксплойта нет | Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalationpickplugins · post grid · CWE-266 | Высокая8,8 | — | 9,4 % | 11 сент. 2024 г. |
36Наблюдать | CVE-2020-35939Эксплойта нет | PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to injectpickplugins · post grid · CWE-502 | Высокая8,8 | — | 2,1 % | 31 дек. 2020 г. |
36Наблюдать | CVE-2020-35938Эксплойта нет | PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbipickplugins · post grid · CWE-502 | Высокая8,8 | — | 2,1 % | 31 дек. 2020 г. |
35Наблюдать | CVE-2024-13408Эксплойта нет | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusionpickplugins · post grid · CWE-98 | Высокая8,8 | — | 0,6 % | 24 янв. 2025 г. |
35Наблюдать | CVE-2021-4450Эксплойта нет | Post Grid <= 2.1.12 - Contributor+ SQL Injectionpickplugins · post grid · CWE-89 | Высокая8,8 | — | 0,5 % | 16 окт. 2024 г. |
33Наблюдать | CVE-2020-35936Эксплойта нет | Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers tpickplugins · post grid · CWE-79 | Высокая8,0 | — | 1,7 % | 31 дек. 2020 г. |
33Наблюдать | CVE-2020-35937Эксплойта нет | Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackpickplugins · post grid · CWE-79 | Высокая8,0 | — | 1,7 % | 31 дек. 2020 г. |
31Наблюдать | CVE-2023-40211Proof of concept | WordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data Exposurepickplugins · post grid combo · CWE-200 | Высокая7,5 | — | 2,2 % | 30 нояб. 2023 г. |
30Наблюдать | CVE-2024-32816Эксплойта нет | WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerabilitypickplugins · post grid · CWE-200 | Высокая7,5 | — | 0,7 % | 24 апр. 2024 г. |
30Наблюдать | CVE-2023-7072Эксплойта нет | Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpointpickplugins · post grid combo · CWE-202 | Высокая7,5 | — | 0,6 % | 12 мар. 2024 г. |
30Наблюдать | CVE-2024-38726Эксплойта нет | WordPress Product Designer plugin <= 1.0.33 - Arbitrary Content Deletion vulnerabilitypickplugins · product designer · CWE-862 | Высокая7,5 | — | 0,5 % | 1 нояб. 2024 г. |
30Наблюдать | CVE-2024-13796Эксплойта нет | Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposurepickplugins · post grid · CWE-200 | Высокая7,5 | — | 0,4 % | 28 февр. 2025 г. |
27Наблюдать | CVE-2021-24488Proof of concept | Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)pickplugins · post grid · CWE-79 | Средняя6,1 | — | 11,2 % | 2 авг. 2021 г. |
27Наблюдать | CVE-2021-24300Proof of concept | PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)pickplugins · product slider for woocommerce · CWE-79 | Средняя6,1 | — | 10,6 % | 24 мая 2021 г. |
26Наблюдать | CVE-2024-0881Proof of concept | Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Accesspickplugins · post grid · CWE-863 | Средняя5,4 | — | 16,9 % | 11 апр. 2024 г. |
25Наблюдать | CVE-2022-0447Эксплойта нет | Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_typespickplugins · post grid · CWE-79 | Средняя6,4 | — | 0,6 % | 11 апр. 2022 г. |
25Наблюдать | CVE-2024-7588Эксплойта нет | Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Blockpickplugins · post grid · CWE-79 | Средняя6,4 | — | 0,3 % | 14 авг. 2024 г. |
25Наблюдать | CVE-2024-3155Эксплойта нет | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scrpickplugins · post grid · CWE-79 | Средняя6,4 | — | 0,3 % | 20 мая 2024 г. |
24Наблюдать | CVE-2021-24986Эксплойта нет | Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keywordpickplugins · post grid · CWE-79 | Средняя6,1 | — | 0,8 % | 11 апр. 2022 г. |
24Наблюдать | CVE-2024-45459Эксплойта нет | WordPress Product Slider for WooCommerce by PickPlugins plugin <= 1.13.50 - Reflected Cross Site Scripting (XSS) vulnerabilitypickplugins · product slider for woocommerce · CWE-79 | Средняя6,1 | — | 0,3 % | 15 сент. 2024 г. |
24Наблюдать | CVE-2024-44002Эксплойта нет | WordPress Team Showcase plugin <= 1.22.25 - Reflected Cross Site Scripting (XSS) vulnerabilitypickplugins · team showcase · CWE-79 | Средняя6,1 | — | 0,3 % | 17 сент. 2024 г. |
21Наблюдать | CVE-2020-13644Эксплойта нет | An issue was discovered in the Accordion plugin before 2.2.9 for WordPress.pickplugins · accordion · CWE-79 | Средняя5,4 | — | 0,8 % | 28 мая 2020 г. |
21Наблюдать | CVE-2021-24283Эксплойта нет | Accordion < 2.2.30 - Authenticated Reflected Cross-Site Scripting (XSS)pickplugins · accordion · CWE-79 | Средняя5,4 | — | 0,6 % | 14 мая 2021 г. |
21Наблюдать | CVE-2022-4836Эксплойта нет | Breadcrumb < 1.5.33 - Contributor+ Stored XSS via Shortcodepickplugins · breadcrumb · CWE-79 | Средняя5,4 | — | 0,6 % | 6 февр. 2023 г. |
- CVE-2022-469339Наблюдать
User Verification < 1.0.94 - Authentication Bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %pickplugins · user verification23 янв. 2023 г.
- CVE-2024-825338Наблюдать
Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 9 %pickplugins · post grid11 сент. 2024 г.
- CVE-2020-3593936Наблюдать
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %pickplugins · post grid31 дек. 2020 г.
- CVE-2020-3593836Наблюдать
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbi
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %pickplugins · post grid31 дек. 2020 г.
- CVE-2024-1340835Наблюдать
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %pickplugins · post grid24 янв. 2025 г.
- CVE-2021-445035Наблюдать
Post Grid <= 2.1.12 - Contributor+ SQL Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %pickplugins · post grid16 окт. 2024 г.
- CVE-2020-3593633Наблюдать
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers t
ВысокаяCVSS 8,0Эксплойта нетEPSS 2 %pickplugins · post grid31 дек. 2020 г.
- CVE-2020-3593733Наблюдать
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attack
ВысокаяCVSS 8,0Эксплойта нетEPSS 2 %pickplugins · post grid31 дек. 2020 г.
- CVE-2023-4021131Наблюдать
WordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data Exposure
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %pickplugins · post grid combo30 нояб. 2023 г.
- CVE-2024-3281630Наблюдать
WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %pickplugins · post grid24 апр. 2024 г.
- CVE-2023-707230Наблюдать
Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %pickplugins · post grid combo12 мар. 2024 г.
- CVE-2024-3872630Наблюдать
WordPress Product Designer plugin <= 1.0.33 - Arbitrary Content Deletion vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %pickplugins · product designer1 нояб. 2024 г.
- CVE-2024-1379630Наблюдать
Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %pickplugins · post grid28 февр. 2025 г.
- CVE-2021-2448827Наблюдать
Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
СредняяCVSS 6,1Proof of conceptEPSS 11 %pickplugins · post grid2 авг. 2021 г.
- CVE-2021-2430027Наблюдать
PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)
СредняяCVSS 6,1Proof of conceptEPSS 11 %pickplugins · product slider for woocommerce24 мая 2021 г.
- CVE-2024-088126Наблюдать
Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access
СредняяCVSS 5,4Proof of conceptEPSS 17 %pickplugins · post grid11 апр. 2024 г.
- CVE-2022-044725Наблюдать
Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types
СредняяCVSS 6,4Эксплойта нетEPSS 1 %pickplugins · post grid11 апр. 2022 г.
- CVE-2024-758825Наблюдать
Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block
СредняяCVSS 6,4Эксплойта нетEPSS 0 %pickplugins · post grid14 авг. 2024 г.
- CVE-2024-315525Наблюдать
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scr
СредняяCVSS 6,4Эксплойта нетEPSS 0 %pickplugins · post grid20 мая 2024 г.
- CVE-2021-2498624Наблюдать
Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keyword
СредняяCVSS 6,1Эксплойта нетEPSS 1 %pickplugins · post grid11 апр. 2022 г.
- CVE-2024-4545924Наблюдать
WordPress Product Slider for WooCommerce by PickPlugins plugin <= 1.13.50 - Reflected Cross Site Scripting (XSS) vulnerability
СредняяCVSS 6,1Эксплойта нетEPSS 0 %pickplugins · product slider for woocommerce15 сент. 2024 г.
- CVE-2024-4400224Наблюдать
WordPress Team Showcase plugin <= 1.22.25 - Reflected Cross Site Scripting (XSS) vulnerability
СредняяCVSS 6,1Эксплойта нетEPSS 0 %pickplugins · team showcase17 сент. 2024 г.
- CVE-2020-1364421Наблюдать
An issue was discovered in the Accordion plugin before 2.2.9 for WordPress.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %pickplugins · accordion28 мая 2020 г.
- CVE-2021-2428321Наблюдать
Accordion < 2.2.30 - Authenticated Reflected Cross-Site Scripting (XSS)
СредняяCVSS 5,4Эксплойта нетEPSS 1 %pickplugins · accordion14 мая 2021 г.
- CVE-2022-483621Наблюдать
Breadcrumb < 1.5.33 - Contributor+ Stored XSS via Shortcode
СредняяCVSS 5,4Эксплойта нетEPSS 1 %pickplugins · breadcrumb6 февр. 2023 г.