PickPlugins Vulnerabilities and Affected Products
Vulnerabilities associated with post_grid.
Products
Clear product- Post Grid12 vulnerabilities
- Job Board Manager9 vulnerabilities
- Post Grid and Gutenberg Blocks8 vulnerabilities
- Wishlist6 vulnerabilities
- Accordion5 vulnerabilities
- post_grid4 vulnerabilities
- post_grid_combo4 vulnerabilities
- Product Slider for WooCommerce3 vulnerabilities
- Question Answer3 vulnerabilities
- Team Showcase3 vulnerabilities
- Testimonial Slider3 vulnerabilities
- Accordions2 vulnerabilities
- Mail Picker2 vulnerabilities
- PickPlugins Product Designer for WooCommerce2 vulnerabilities
- Product Designer2 vulnerabilities
- product_designer2 vulnerabilities
- User Verification by PickPlugins2 vulnerabilities
- ComboBlocks1 vulnerability
- page_builder_comboblocks1 vulnerability
- PickPlugins Pricing Table1 vulnerability
- PickPlugins Product Slider for WooCommerce1 vulnerability
- PickPlugins Question Answer1 vulnerability
- Post Grid and Gutenberg Blocks – ComboBlocks1 vulnerability
- Post Grid Combo – 36+ Gutenberg Blocks1 vulnerability
- product_slider_for_woocommerce1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-4450HIGH | Post Grid <= 2.1.12 - Contributor+ SQL InjectionThe Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level permissions and above to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CWE-89Oct 16, 2024 | CVSS8.8v3.1 | EPSS0.482% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8253HIGH | Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege EscalationThe Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting what user meta values can be updated and ensuring a form is active. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their user meta to become an administrator. CWE-266Sep 11, 2024 | CVSS8.8v3.1 | EPSS9.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32816HIGH | WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerabilityExposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid.This issue affects Post Grid: from n/a through 2.2.78. CWE-200Apr 24, 2024 | CVSS7.5v3.1 | EPSS0.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-0881MEDIUM | Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts AccessThe Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts | CVSS5.4v3.1 | EPSS16.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |