
CVE-2020-35937 – Team Showcase <= 1.22.15 - Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2020-35937
17 Sep 2020 — Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts. Unas vulnerabilidades de tipo Cross-Site Scripting (XSS) almacenado en el plugin Team Showcase versiones anteriores a 1.22.16 para WordPress, permiten a atacantes autenticados remotos importar dise... • https://www.wordfence.com/blog/2020/10/high-severity-vulnerabilities-in-post-grid-and-team-showcase-plugins • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-35938 – Team Showcase <= 1.22.15 - Object Injection
https://notcve.org/view.php?id=CVE-2020-35938
17 Sep 2020 — PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts. Unas vulnerabilidades de inyección de objetos PHP en el plugin Post Grid versiones anteriores a 2.0.73 para WordPress, permiten a atacantes autenticados remotos inyectar objetos ... • https://www.wordfence.com/blog/2020/10/high-severity-vulnerabilities-in-post-grid-and-team-showcase-plugins • CWE-502: Deserialization of Untrusted Data •

CVE-2020-35939 – Team Showcase <= 1.22.15 - Object Injection
https://notcve.org/view.php?id=CVE-2020-35939
17 Sep 2020 — PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts. Unas vulnerabilidades de inyección de objetos PHP en el plugin Team Showcase versiones anteriores a 1.22.16 para WordPress, permiten a atacantes autenticados remotos inyectar obj... • https://www.wordfence.com/blog/2020/10/high-severity-vulnerabilities-in-post-grid-and-team-showcase-plugins • CWE-502: Deserialization of Untrusted Data •

CVE-2020-13644 – Accordion <= 2.2.8 - Unprotected AJAX Action to Stored/Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2020-13644
18 Mar 2020 — An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher permissions the ability to import a new accordion and inject malicious JavaScript as part of the accordion. Se detectó un problema en el plugin Accordion versiones anteriores a 2.2.9 para WordPress. La acción no protegida de AJAX wp_ajax_accordions_ajax_import_json permitió a cualquier usuario autenticado con perm... • https://wordpress.org/plugins/accordions/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •