Loading HuntDB...

pickplugins

21 Products 37 CVEs

CVE Severity Distribution (All Time)

Critical
2
High
10
Medium
23
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 13 CVEs

Recent CVEs

View all
CVE-2024-9636 CRITICAL 7 months, 3 weeks ago

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.3. This is due to the plugin …

CVE-2024-55993 MEDIUM 8 months, 3 weeks ago

Missing Authorization vulnerability in PickPlugins Job Board Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

CVE-2024-54273 CRITICAL 8 months, 4 weeks ago

Deserialization of Untrusted Data vulnerability in PickPlugins Mail Picker allows Object Injection.This issue affects Mail Picker: from n/a through 1…

CVE-2024-10937 MEDIUM 9 months ago

The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Inf…

CVE-2024-53772 MEDIUM 9 months, 1 week ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Mail Picker allows DOM-Based XSS.Th…

CVE-2024-9111 MEDIUM 9 months, 3 weeks ago

The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0…

CVE-2024-38726 HIGH 10 months, 1 week ago

Missing Authorization vulnerability in PickPlugins Product Designer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affect…

CVE-2024-50432 MEDIUM 10 months, 1 week ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Bloc…

CVE-2021-4450 HIGH 10 months, 3 weeks ago

The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficien…

CVE-2024-47340 MEDIUM 11 months ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Bloc…

Related Security News

CVE-2024-9636: Popular WordPress Plugin ComboBlocks Exposes Thousands of Sites to Complete Takeover
2025-01-17 01:45 SecurityOnline.info

A critical vulnerability in the popular WordPress plugin, formerly known as Post Grid and now ComboBlocks, has left The post CVE-2024-9636: Popular WordPress Plugin ComboBlocks Exposes Thousands of S…