Known Vulnerabilities for products from PickPlugins
Listed below are 20 of the newest known vulnerabilities associated with the vendor "PickPlugins".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-10207 json | Not Provided | 2026-07-28 | 2026-07-28 | |
| CVE-2025-62745 json | Not Provided | 2026-05-25 | 2026-05-26 | |
| CVE-2024-45459 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Product Sli... | Not Provided | 2024-09-15 | 2026-04-23 |
| CVE-2024-44002 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showca... | Not Provided | 2024-09-18 | 2026-04-23 |
| CVE-2024-6346 json | The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... | Not Provided | 2024-08-01 | 2026-04-08 |
| CVE-2024-4042 json | The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress ... | Not Provided | 2024-06-07 | 2026-04-08 |
| CVE-2024-1988 json | The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress ... | Not Provided | 2024-06-07 | 2026-04-08 |
| CVE-2023-51666 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Related Pos... | Not Provided | 2024-02-01 | 2026-04-28 |
| CVE-2023-40211 json | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blo... | Not Provided | 2023-11-30 | 2026-04-28 |
| CVE-2023-7072 json | The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers... | Not Provided | 2024-03-12 | 2026-04-08 |
| CVE-2023-6645 json | The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom... | Not Provided | 2024-01-11 | 2026-04-08 |
| CVE-2023-0166 json | The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its sh... | 5.4 - MEDIUM | 2023-02-13 | 2023-11-07 |
| CVE-2022-4836 json | The Breadcrumb WordPress plugin before 1.5.33 does not validate and escape some of its shortcode attributes before outputting... | 5.4 - MEDIUM | 2023-02-06 | 2023-11-07 |
| CVE-2022-4693 json | The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authent... | 9.8 - CRITICAL | 2023-01-23 | 2023-11-07 |
| CVE-2022-0447 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.4 - MEDIUM | 2022-04-11 | 2022-04-15 |
| CVE-2021-24986 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2022-04-11 | 2022-04-15 |
| CVE-2021-24488 json | The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly s... | 6.1 - MEDIUM | 2021-08-02 | 2021-08-10 |
| CVE-2021-24300 json | The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not pr... | 6.1 - MEDIUM | 2021-05-24 | 2021-05-28 |
| CVE-2021-24283 json | The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, leading t... | 5.4 - MEDIUM | 2021-05-14 | 2021-05-21 |
| CVE-2020-35939 json | PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated atta... | 8.8 - HIGH | 2021-01-01 | 2021-01-11 |
Known software with vulnerabilities from PickPlugins
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Pickplugins | Accordion | 1.0 |
| Application | Pickplugins | Team Showcase | 1.22.16 |