PickPlugins Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with PickPlugins products.
Products
- Post Grid12 vulnerabilities
- Job Board Manager9 vulnerabilities
- Post Grid and Gutenberg Blocks8 vulnerabilities
- Wishlist6 vulnerabilities
- Accordion5 vulnerabilities
- post_grid4 vulnerabilities
- post_grid_combo4 vulnerabilities
- Product Slider for WooCommerce3 vulnerabilities
- Question Answer3 vulnerabilities
- Team Showcase3 vulnerabilities
- Testimonial Slider3 vulnerabilities
- Accordions2 vulnerabilities
- Mail Picker2 vulnerabilities
- PickPlugins Product Designer for WooCommerce2 vulnerabilities
- Product Designer2 vulnerabilities
- product_designer2 vulnerabilities
- User Verification by PickPlugins2 vulnerabilities
- ComboBlocks1 vulnerability
- page_builder_comboblocks1 vulnerability
- PickPlugins Pricing Table1 vulnerability
- PickPlugins Product Slider for WooCommerce1 vulnerability
- PickPlugins Question Answer1 vulnerability
- Post Grid and Gutenberg Blocks – ComboBlocks1 vulnerability
- Post Grid Combo – 36+ Gutenberg Blocks1 vulnerability
- product_slider_for_woocommerce1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-10207HIGH | PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id' ParameterThe PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id' GET parameter in the user profile template combined with the use of wp_unslash() which removes WordPress's magic quotes protection, followed by direct concatenation into a SQL query without proper escaping or prepared statements in the qa_user_profile_card() function. This makes it possible for una… CWE-89Jul 28, 2026 | CVSS7.5v3.1 | EPSS0.304% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65456MEDIUM | WordPress Product Slider for WooCommerce plugin <= 1.13.62 - Insecure Direct Object References (IDOR) vulnerabilityContributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions. CWE-639Jul 23, 2026 | CVSS4.3v3.1 | EPSS0.197% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-10862MEDIUM | Accordions <= 2.3.23 - Authenticated (Custom+) Stored Cross-Site Scripting via Accordion Body FieldThe Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all versions up to, and including, 2.3.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Jun 9, 2026 | CVSS6.4v3.1 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62745MEDIUM | WordPress Team Showcase plugin <= 1.22.28 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. This issue affects Team Showcase: from n/a through 1.22.28. CWE-79May 25, 2026 | CVSS6.5v3.1 | EPSS0.171% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7458CRITICAL | User Verification by PickPlugins <= 2.0.46 - Unauthenticated Authentication Bypass via OTP Verification REST API EndpointThe User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting a "true" OTP value. CWE-288May 2, 2026 | CVSS9.8v3.1 | EPSS0.578% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32497MEDIUM | WordPress User Verification plugin <= 2.0.45 - Email Verification Bypass vulnerabilityWeak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This issue affects User Verification: from n/a through <= 2.0.45. CWE-1390Mar 25, 2026 | CVSS5.3v3.1 | EPSS0.221% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25455MEDIUM | WordPress Product Slider for WooCommerce plugin <= 1.13.61 - Broken Access Control vulnerabilityMissing Authorization vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Slider for WooCommerce: from n/a through <= 1.13.61. CWE-862Mar 25, 2026 | CVSS6.5v3.1 | EPSS0.315% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68000MEDIUM | WordPress Testimonial Slider plugin <= 2.0.15 - Broken Access Control vulnerabilityMissing Authorization vulnerability in PickPlugins Testimonial Slider testimonial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Testimonial Slider: from n/a through <= 2.0.15. CWE-862Feb 20, 2026 | CVSS6.5v3.1 | EPSS0.315% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68605MEDIUM | WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.23 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23. CWE-79Dec 24, 2025 | CVSS6.5v3.1 | EPSS0.138% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-63043MEDIUM | WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.23 - Insecure Direct Object References (IDOR) vulnerabilityAuthorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23. CWE-639Dec 18, 2025 | CVSS5.3v3.1 | EPSS0.216% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66058MEDIUM | WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.17 - Broken Access Control vulnerabilityMissing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.17. CWE-862Dec 18, 2025 | CVSS6.5v3.1 | EPSS0.213% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-12374CRITICAL | Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification <= 2.0.44 - Authentication Bypass to Account TakeoverThe Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.44. This is due to the plugin not properly validating that an OTP was generated before comparing it to user input in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email addres… CWE-287Dec 5, 2025 | CVSS9.8v3.1 | EPSS0.507% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62929MEDIUM | WordPress Testimonial Slider plugin <= 2.0.15 - Broken Access Control vulnerabilityMissing Authorization vulnerability in PickPlugins Testimonial Slider testimonial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Testimonial Slider: from n/a through <= 2.0.15. CWE-862Oct 27, 2025 | CVSS6.5v3.1 | EPSS0.308% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62924MEDIUM | WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.17 - Broken Access Control vulnerabilityMissing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.17. CWE-862Oct 27, 2025 | CVSS6.5v3.1 | EPSS0.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53421MEDIUM | WordPress Accordion plugin <= 2.3.14 - Broken Access Control vulnerabilityMissing Authorization vulnerability in PickPlugins Accordion accordions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion: from n/a through <= 2.3.14. CWE-862Oct 22, 2025 | CVSS6.5v3.1 | EPSS0.294% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-60162MEDIUM | WordPress Job Board Manager Plugin <= 2.1.61 - Cross Site Scripting (XSS) VulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager job-board-manager allows DOM-Based XSS.This issue affects Job Board Manager: from n/a through <= 2.1.61. CWE-79Sep 26, 2025 | CVSS6.5v3.1 | EPSS0.203% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58678MEDIUM | WordPress Accordion Plugin <= 2.3.15 - Broken Access Control VulnerabilityMissing Authorization vulnerability in PickPlugins Accordion accordions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion: from n/a through <= 2.3.15. CWE-862Sep 22, 2025 | CVSS6.5v3.1 | EPSS0.294% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
WordPress Job Board Manager Plugin <= 2.1.61 - Content Injection VulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61. CWE-94Sep 5, 2025 | CVSS3.8v3.1 | EPSS0.249% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-54007HIGH | WordPress Post Grid and Gutenberg Blocks Plugin <= 2.3.11 - PHP Object Injection VulnerabilityDeserialization of Untrusted Data vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Object Injection.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.11. CWE-502Aug 20, 2025 | CVSS8.8v3.1 | EPSS0.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49324MEDIUM | WordPress Job Board Manager plugin <= 2.1.60 - Broken Access Control VulnerabilityMissing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.60. CWE-862Jun 6, 2025 | CVSS5.3v3.1 | EPSS0.273% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49075MEDIUM | WordPress Wishlist plugin <= 1.0.43 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Wishlist wishlist allows Stored XSS.This issue affects Wishlist: from n/a through <= 1.0.43. CWE-79Jun 6, 2025 | CVSS6.5v3.1 | EPSS0.169% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24655HIGH | WordPress Wishlist Plugin <= 1.0.39 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Wishlist wishlist allows Reflected XSS.This issue affects Wishlist: from n/a through <= 1.0.39. CWE-79Apr 17, 2025 | CVSS7.1v3.1 | EPSS0.276% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-32646HIGH | WordPress Question Answer plugin <= 1.2.70 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Question Answer question-answer allows Reflected XSS.This issue affects Question Answer: from n/a through <= 1.2.70. CWE-79Apr 17, 2025 | CVSS7.1v3.1 | EPSS0.276% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-32647HIGH | WordPress Question Answer plugin <= 1.2.73 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in PickPlugins Question Answer question-answer allows Object Injection.This issue affects Question Answer: from n/a through <= 1.2.73. CWE-502Apr 17, 2025 | CVSS8.8v3.1 | EPSS0.45% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-32618HIGH | WordPress Wishlist plugin <= 1.0.46 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist wishlist allows SQL Injection.This issue affects Wishlist: from n/a through <= 1.0.46. CWE-89Apr 11, 2025 | CVSS8.5v3.1 | EPSS0.462% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |