cbcvebase.

Pickplugins Post Grid vulnerabilities

23 known vulnerabilities affecting pickplugins/post_grid.

Total CVEs
23
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH11MEDIUM12

Vulnerabilities

Page 2 of 2
CVE-2023-6645P4MEDIUMCVSS 5.4≤ 2.2.642024-01-11
CVE-2023-6645 [MEDIUM] CWE-79 CVE-2023-6645: The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site S The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.2.64 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher to inject arbitrary web sc
nvd
CVE-2024-6346P4MEDIUMCVSS 5.4≤ 2.2.852024-08-01
CVE-2024-6346 [MEDIUM] CWE-79 CVE-2024-6346: The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross- The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the redirectURL parameter of the Date Countdown widget, in all versions up to, and including, 2.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac
nvd
CVE-2024-1988P4MEDIUMCVSS 5.4fixed in 2.2.81≤ 2.2.802024-06-07
CVE-2024-1988 [MEDIUM] CWE-79 CVE-2024-1988: The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Block The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute in blocks in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack
nvd
Pickplugins Post Grid vulnerabilities | cvebase