PickPlugins kayıtları
pickplugins üreticisine ait 36 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %25
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-862 Missing Authorization2
- CWE-502 Deserialization of Untrusted Data2
- CWE-522 Insufficiently Protected Credentials1
- CWE-863 Incorrect Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
36 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-4693İstismar yok | User Verification < 1.0.94 - Authentication Bypasspickplugins · user verification · CWE-522 | Kritik9,8 | — | %1,6 | 23 Oca 2023 |
38İzleyin | CVE-2024-8253İstismar yok | Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalationpickplugins · post grid · CWE-266 | Yüksek8,8 | — | %9,4 | 11 Eyl 2024 |
36İzleyin | CVE-2020-35939İstismar yok | PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to injectpickplugins · post grid · CWE-502 | Yüksek8,8 | — | %2,1 | 31 Ara 2020 |
36İzleyin | CVE-2020-35938İstismar yok | PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbipickplugins · post grid · CWE-502 | Yüksek8,8 | — | %2,1 | 31 Ara 2020 |
35İzleyin | CVE-2024-13408İstismar yok | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusionpickplugins · post grid · CWE-98 | Yüksek8,8 | — | %0,6 | 24 Oca 2025 |
35İzleyin | CVE-2021-4450İstismar yok | Post Grid <= 2.1.12 - Contributor+ SQL Injectionpickplugins · post grid · CWE-89 | Yüksek8,8 | — | %0,5 | 16 Eki 2024 |
33İzleyin | CVE-2020-35936İstismar yok | Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers tpickplugins · post grid · CWE-79 | Yüksek8,0 | — | %1,7 | 31 Ara 2020 |
33İzleyin | CVE-2020-35937İstismar yok | Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackpickplugins · post grid · CWE-79 | Yüksek8,0 | — | %1,7 | 31 Ara 2020 |
31İzleyin | CVE-2023-40211Kavram kanıtı | WordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data Exposurepickplugins · post grid combo · CWE-200 | Yüksek7,5 | — | %2,2 | 30 Kas 2023 |
30İzleyin | CVE-2024-32816İstismar yok | WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerabilitypickplugins · post grid · CWE-200 | Yüksek7,5 | — | %0,7 | 24 Nis 2024 |
30İzleyin | CVE-2023-7072İstismar yok | Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpointpickplugins · post grid combo · CWE-202 | Yüksek7,5 | — | %0,6 | 12 Mar 2024 |
30İzleyin | CVE-2024-38726İstismar yok | WordPress Product Designer plugin <= 1.0.33 - Arbitrary Content Deletion vulnerabilitypickplugins · product designer · CWE-862 | Yüksek7,5 | — | %0,5 | 1 Kas 2024 |
30İzleyin | CVE-2024-13796İstismar yok | Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposurepickplugins · post grid · CWE-200 | Yüksek7,5 | — | %0,4 | 28 Şub 2025 |
27İzleyin | CVE-2021-24488Kavram kanıtı | Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)pickplugins · post grid · CWE-79 | Orta6,1 | — | %11,2 | 2 Ağu 2021 |
27İzleyin | CVE-2021-24300Kavram kanıtı | PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)pickplugins · product slider for woocommerce · CWE-79 | Orta6,1 | — | %10,6 | 24 May 2021 |
26İzleyin | CVE-2024-0881Kavram kanıtı | Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Accesspickplugins · post grid · CWE-863 | Orta5,4 | — | %16,9 | 11 Nis 2024 |
25İzleyin | CVE-2022-0447İstismar yok | Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_typespickplugins · post grid · CWE-79 | Orta6,4 | — | %0,6 | 11 Nis 2022 |
25İzleyin | CVE-2024-7588İstismar yok | Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Blockpickplugins · post grid · CWE-79 | Orta6,4 | — | %0,3 | 14 Ağu 2024 |
25İzleyin | CVE-2024-3155İstismar yok | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scrpickplugins · post grid · CWE-79 | Orta6,4 | — | %0,3 | 20 May 2024 |
24İzleyin | CVE-2021-24986İstismar yok | Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keywordpickplugins · post grid · CWE-79 | Orta6,1 | — | %0,8 | 11 Nis 2022 |
24İzleyin | CVE-2024-45459İstismar yok | WordPress Product Slider for WooCommerce by PickPlugins plugin <= 1.13.50 - Reflected Cross Site Scripting (XSS) vulnerabilitypickplugins · product slider for woocommerce · CWE-79 | Orta6,1 | — | %0,3 | 15 Eyl 2024 |
24İzleyin | CVE-2024-44002İstismar yok | WordPress Team Showcase plugin <= 1.22.25 - Reflected Cross Site Scripting (XSS) vulnerabilitypickplugins · team showcase · CWE-79 | Orta6,1 | — | %0,3 | 17 Eyl 2024 |
21İzleyin | CVE-2020-13644İstismar yok | An issue was discovered in the Accordion plugin before 2.2.9 for WordPress.pickplugins · accordion · CWE-79 | Orta5,4 | — | %0,8 | 28 May 2020 |
21İzleyin | CVE-2021-24283İstismar yok | Accordion < 2.2.30 - Authenticated Reflected Cross-Site Scripting (XSS)pickplugins · accordion · CWE-79 | Orta5,4 | — | %0,6 | 14 May 2021 |
21İzleyin | CVE-2022-4836İstismar yok | Breadcrumb < 1.5.33 - Contributor+ Stored XSS via Shortcodepickplugins · breadcrumb · CWE-79 | Orta5,4 | — | %0,6 | 6 Şub 2023 |
- CVE-2022-469339İzleyin
User Verification < 1.0.94 - Authentication Bypass
KritikCVSS 9,8İstismar yokEPSS %2pickplugins · user verification23 Oca 2023
- CVE-2024-825338İzleyin
Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation
YüksekCVSS 8,8İstismar yokEPSS %9pickplugins · post grid11 Eyl 2024
- CVE-2020-3593936İzleyin
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject
YüksekCVSS 8,8İstismar yokEPSS %2pickplugins · post grid31 Ara 2020
- CVE-2020-3593836İzleyin
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbi
YüksekCVSS 8,8İstismar yokEPSS %2pickplugins · post grid31 Ara 2020
- CVE-2024-1340835İzleyin
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion
YüksekCVSS 8,8İstismar yokEPSS %1pickplugins · post grid24 Oca 2025
- CVE-2021-445035İzleyin
Post Grid <= 2.1.12 - Contributor+ SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %0pickplugins · post grid16 Eki 2024
- CVE-2020-3593633İzleyin
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers t
YüksekCVSS 8,0İstismar yokEPSS %2pickplugins · post grid31 Ara 2020
- CVE-2020-3593733İzleyin
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attack
YüksekCVSS 8,0İstismar yokEPSS %2pickplugins · post grid31 Ara 2020
- CVE-2023-4021131İzleyin
WordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data Exposure
YüksekCVSS 7,5Kavram kanıtıEPSS %2pickplugins · post grid combo30 Kas 2023
- CVE-2024-3281630İzleyin
WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1pickplugins · post grid24 Nis 2024
- CVE-2023-707230İzleyin
Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint
YüksekCVSS 7,5İstismar yokEPSS %1pickplugins · post grid combo12 Mar 2024
- CVE-2024-3872630İzleyin
WordPress Product Designer plugin <= 1.0.33 - Arbitrary Content Deletion vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0pickplugins · product designer1 Kas 2024
- CVE-2024-1379630İzleyin
Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure
YüksekCVSS 7,5İstismar yokEPSS %0pickplugins · post grid28 Şub 2025
- CVE-2021-2448827İzleyin
Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
OrtaCVSS 6,1Kavram kanıtıEPSS %11pickplugins · post grid2 Ağu 2021
- CVE-2021-2430027İzleyin
PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)
OrtaCVSS 6,1Kavram kanıtıEPSS %11pickplugins · product slider for woocommerce24 May 2021
- CVE-2024-088126İzleyin
Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access
OrtaCVSS 5,4Kavram kanıtıEPSS %17pickplugins · post grid11 Nis 2024
- CVE-2022-044725İzleyin
Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types
OrtaCVSS 6,4İstismar yokEPSS %1pickplugins · post grid11 Nis 2022
- CVE-2024-758825İzleyin
Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block
OrtaCVSS 6,4İstismar yokEPSS %0pickplugins · post grid14 Ağu 2024
- CVE-2024-315525İzleyin
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scr
OrtaCVSS 6,4İstismar yokEPSS %0pickplugins · post grid20 May 2024
- CVE-2021-2498624İzleyin
Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keyword
OrtaCVSS 6,1İstismar yokEPSS %1pickplugins · post grid11 Nis 2022
- CVE-2024-4545924İzleyin
WordPress Product Slider for WooCommerce by PickPlugins plugin <= 1.13.50 - Reflected Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0pickplugins · product slider for woocommerce15 Eyl 2024
- CVE-2024-4400224İzleyin
WordPress Team Showcase plugin <= 1.22.25 - Reflected Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0pickplugins · team showcase17 Eyl 2024
- CVE-2020-1364421İzleyin
An issue was discovered in the Accordion plugin before 2.2.9 for WordPress.
OrtaCVSS 5,4İstismar yokEPSS %1pickplugins · accordion28 May 2020
- CVE-2021-2428321İzleyin
Accordion < 2.2.30 - Authenticated Reflected Cross-Site Scripting (XSS)
OrtaCVSS 5,4İstismar yokEPSS %1pickplugins · accordion14 May 2021
- CVE-2022-483621İzleyin
Breadcrumb < 1.5.33 - Contributor+ Stored XSS via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %1pickplugins · breadcrumb6 Şub 2023