Filter
-Infinity
0

WishlistWordPress Wishlist Plugin <= 1.0.39 - Reflected Cross Site Scripting (XSS) vulnerability

7.1
First published (updated )

PickPlugins Question AnswerWordPress Question Answer Plugin <= 1.2.70 - Reflected Cross Site Scripting (XSS) vulnerability

7.1
EPSS
0.04%
First published (updated )

WishlistWordPress Wishlist Plugin <= 1.0.44 - Cross Site Request Forgery (CSRF) vulnerability

EPSS
0.02%
First published (updated )

PickPlugins Testimonial SliderWordPress Testimonial Slider plugin <= 2.0.13 - PHP Object Injection vulnerability

8.8
EPSS
0.05%
First published (updated )

PickPlugins Question AnswerWordPress Question Answer Plugin <= 1.2.70 - Broken Access Control vulnerability

EPSS
0.04%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

PickPlugins Related PostsRelated Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.59 - Cross-Site Request Forgery to Stored Cross-Site Scripting

First published (updated )

Pickplugins Pricing TablePricing Table by PickPlugins <= 1.12.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

First published (updated )

PickPlugins Post GridPost Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure

7.5
First published (updated )

WishlistWordPress Wishlist Plugin <= 1.0.41 - SQL Injection vulnerability

8.5
EPSS
0.04%
First published (updated )

PickPlugins ComboBlocksPost Grid and Gutenberg Blocks – ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Job Board Manager PluginXSS

7.1
EPSS
0.04%
First published (updated )

Job Board Manager PluginWordPress Job Board Manager plugin <= 2.1.59 - Cross Site Request Forgery (CSRF) vulnerability

EPSS
0.04%
First published (updated )

PickPlugins Post GridPost Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion

8.8
First published (updated )

Job Board Manager PluginWordPress Job Board Manager plugin <= 2.1.60 - Broken Access Control vulnerability

First published (updated )

PickPlugins Related PostsRelated Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.58 - Sensitive Information Exposure

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

PickPlugins Product DesignerWordPress Product Designer plugin <= 1.0.33 - Arbitrary Content Deletion vulnerability

7.5
First published (updated )

ComboBlocks Post Grid and Gutenberg BlocksWordPress Post Grid and Gutenberg Blocks plugin <= 2.2.93 - Cross Site Scripting (XSS) vulnerability

First published (updated )

PickPlugins Post GridPost Grid <= 2.1.12 - Contributor+ SQL Injection

8.8
First published (updated )

ComboBlocks Post Grid and Gutenberg BlocksWordPress ComboBlocks plugin <= 2.2.89 - Cross Site Scripting (XSS) vulnerability

First published (updated )

PickPlugins Tabs & AccordionWordPress Accordion plugin <= 2.2.99 - Cross Site Scripting (XSS) vulnerability

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

PickPlugins Team ShowcaseWordPress Team Showcase plugin <= 1.22.25 - Reflected Cross Site Scripting (XSS) vulnerability

7.1
First published (updated )

PickPlugins Product Slider for WooCommerceWordPress Product Slider for WooCommerce by PickPlugins plugin <= 1.13.50 - Reflected Cross Site Scripting (XSS) vulnerability

7.1
First published (updated )

PickPlugins Post GridPost Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation

8.8
EPSS
0.07%
First published (updated )

WordPress ComboBlocksWordPress ComboBlocks plugin <= 2.2.86 - Cross Site Scripting (XSS) vulnerability

First published (updated )

Combo BlocksPost Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.85a - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget

EPSS
0.05%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Job Board Manager PluginWordPress Job Board Manager plugin <= 2.1.57 - Cross Site Scripting (XSS) vulnerability

First published (updated )

PickPlugins ComboBlocksPost Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute

EPSS
0.04%
First published (updated )

PickPlugins Post GridPost Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting

First published (updated )

PickPlugins Product DesignerWordPress Product Designer plugin <= 1.0.32 - PHP Object Injection vulnerability

8.7
EPSS
0.04%
First published (updated )

PickPlugins User ProfileWordPress User profile plugin <= 2.0.20 - Subscriber+ Stored Cross Site Scripting (XSS) vulnerability

EPSS
0.04%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203