Extension WordPress
Vulnérabilités Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget
Cette page rassemble les failles publiées pour Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget
8 fiches
Post Grid, Slider & Carousel Ultimate <= 1.6.10 – Authenticated (Contributor+) Local File Inclusion
The Post Grid, Slider & Carousel Ultimate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.10. This makes it possible for authenticated attackers, with contributor-level access and above, to include and…
*-1.6.10
1.7
27/01/2025
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 – Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler()
The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 via the 'theme' parameter of the…
*-1.6.10
1.7
23/01/2025
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 – Authenticated (Contributor+) Local File Inclusion
The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 via the 'theme' attribute of the…
*-1.6.10
1.7
23/01/2025
Post Grid, Slider & Carousel Ultimate <= 1.6.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Post Grid, Slider & Carousel Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-1.6.6
1.6.7
25/03/2024
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.7 – Authenticated (Contributor+) PHP Object Injection in outpost_shortcode_metabox_markup
The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.7 via deserialization of untrusted input in…
*-1.6.7
1.6.8
05/03/2024
Appsero <= 1.2.1 – Missing Authorization
The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible…
*-1.6.3
1.6.4
16/12/2022
Appsero <= 1.2.0 – Cross-Site Request Forgery
The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it…
*-1.6.3
1.6.4
14/12/2022
Post Grid, Slider & Carousel Ultimate <= 1.4.3 – Authenticated (Admin+) Cross-Site Scripting
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
[*, 1.5.0)
1.5.0
26/05/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.