
CVE-2023-0166 – PickPlugins Product Slider for WooCommerce < 1.13.42 - Contributor+ Stored XSS
https://notcve.org/view.php?id=CVE-2023-0166
23 Jan 2023 — The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The PickPlugins Product Slider for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.13.41 du... • https://wpscan.com/vulnerability/f5d43062-4ef3-4dd1-b916-0127f0016f5c • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-4836 – Breadcrumb < 1.5.33 - Contributor+ Stored XSS via Shortcode
https://notcve.org/view.php?id=CVE-2022-4836
11 Jan 2023 — The Breadcrumb WordPress plugin before 1.5.33 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. The Breadcrumb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'breadcrumb_themes' (within in the 'breadcrumb_display' function) in versions up to, and including, 1.5.32 d... • https://wpscan.com/vulnerability/e9a228dc-d32e-4918-898d-4d7af4662a14 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-4693 – User Verification < 1.0.94 - Authentication Bypass
https://notcve.org/view.php?id=CVE-2022-4693
28 Dec 2022 — The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depending on whose username we know, which can be easily queried because it is usually public data, we may even be given an administrative role on the website. El complemento User Verification de WordPress anterior a la versión 1.0.94 se vio afectado por una vulnerabilidad de seguridad de Auth Bypass. Para evitar la autenticación, sól... • https://lana.codes/lanavdb/eeabe1d3-6f64-400a-8fb2-0865efdf6957 • CWE-287: Improper Authentication CWE-522: Insufficiently Protected Credentials •

CVE-2022-0447 – Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types
https://notcve.org/view.php?id=CVE-2022-0447
15 Mar 2022 — The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting El plugin Post Grid de WordPress versiones anteriores a 2.1.16, no sanea ni escapa del parámetro post_types antes de devolverlo en la respuesta de la acción AJAX post_grid_update_taxonomies_terms_by_posttypes, disponible p... • https://wpscan.com/vulnerability/91ca2cc9-951e-4e96-96ff-3bf131209dbe • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24986 – Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keyword
https://notcve.org/view.php?id=CVE-2021-24986
15 Mar 2022 — The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form El plugin Post Grid de WordPress versiones anteriores a 2.1.16, no escapa el parámetro keyword antes de devolverlo en un atributo, conllevando a una vulnerabilidad de tipo Cross-Site Scripting Reflejado en páginas que contienen un Post Grid con un formulario de búsqueda • https://wpscan.com/vulnerability/51e57f25-b8b2-44ca-9162-d7328eac64eb • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-4450 – Post Grid <= 2.1.12 - Contributor+ SQL Injection
https://notcve.org/view.php?id=CVE-2021-4450
15 Dec 2021 — The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level permissions and above to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. • https://www.wordfence.com/threat-intel/vulnerabilities/id/a321b112-ce37-4a0e-800f-f3feef6ac799?source=cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-24488 – Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2021-24488
28 Jun 2021 — The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues La funcionalidad slider import search y el parámetro tab del plugin Post Grid WordPress versiones anteriores a 2.1.8, no son saneados apropiadamente antes de ser devueltos a las páginas, lo que conlleva a problemas de tipo Cross-Site Scripting reflejado WordPress Post Grid plugin version 2... • https://packetstorm.news/files/id/165804 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24300 – PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2021-24300
06 May 2021 — The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue La funcionalidad slider import search del plugin PickPlugins Product Slider para WooCommerce WordPress versiones anteriores a 1.13.22 no saneaba apropiadamente el parámetro GET de la palabra clave, conllevando a un problema de tipo Cross-Site Scripting reflejado WordPress Product Slider for Woo... • https://packetstorm.news/files/id/165805 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24283 – Accordion < 2.2.30 - Authenticated Reflected Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2021-24283
21 Apr 2021 — The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, leading to a reflected XSS issue. El parámetro tab GET de la página de configuración no se sanea ni se escapa al ser devuelto en un atributo HTML, conllevando a un problema de tipo XSS reflejado • https://wpscan.com/vulnerability/6ccd9990-e15f-4800-b499-f7c74b480051 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-35936 – Team Showcase <= 1.22.15 - Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2020-35936
17 Sep 2020 — Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts. Unas vulnerabilidades de tipo Cross-Site Scripting (XSS) almacenado en el plugin Post Grid versiones anteriores a 2.0.73 para WordPress, permiten a atacantes autenticados remotos importar diseños q... • https://www.wordfence.com/blog/2020/10/high-severity-vulnerabilities-in-post-grid-and-team-showcase-plugins • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •