Extension WordPress
Vulnérabilités Smart Post – Post Grid, Post Carousel, Post Slider Gutenberg Blocks for Blog & News
Cette page rassemble les failles publiées pour Smart Post – Post Grid, Post Carousel, Post Slider Gutenberg Blocks for Blog & News, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Smart Post – Post Grid, Post Carousel, Post Slider Gutenberg Blocks for Blog & News
5 fiches
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 – Authenticated (Administrator+) PHP Object Injection
The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in…
*-3.0.12
3.0.13
13/04/2026
Smart Post Show <= 3.0.0 – Authenticated (Editor+) Stored Cross-Site Scripting via Pagination Color
The Smart Post Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pagination Color setting in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible…
*-3.0.0
3.0.1
08/10/2024
Post Grid, Post Carousel, & List Category Posts <= 2.4.27 – Authenticated (Editor+) Stored Cross-Site Scripting
The Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin…
*-2.4.27
2.4.28
04/04/2024
Post Grid, Post Carousel, & List Category Posts <= 2.4.18 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Post Grid, Post Carousel, & List Category Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping on…
*-2.4.18
2.4.19
06/01/2023
Post Carousel < 2.3.5 – Missing Capabilities Check
The Post Carousel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on multiple functions in versions up to, and including, 2.3.4. This makes it possible for attackers to improperly access administrative actions.
[*, 2.3.5)
2.3.5
16/08/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.