Extension WordPress

Vulnérabilités Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Cette page rassemble les failles publiées pour Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
0Critiques
8Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

8 fiches

CVE-2025-24782 Élevée · 8,8
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Post Grid, Slider & Carousel Ultimate <= 1.6.10 – Authenticated (Contributor+) Local File Inclusion

The Post Grid, Slider & Carousel Ultimate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.10. This makes it possible for authenticated attackers, with contributor-level access and above, to include and…

Versions affectées

*-1.6.10

Correctif

1.7

Publication

27/01/2025

CVE-2024-13409 Élevée · 7,5
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 – Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler()

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 via the 'theme' parameter of the…

Versions affectées

*-1.6.10

Correctif

1.7

Publication

23/01/2025

CVE-2024-13408 Élevée · 7,5
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 – Authenticated (Contributor+) Local File Inclusion

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 via the 'theme' attribute of the…

Versions affectées

*-1.6.10

Correctif

1.7

Publication

23/01/2025

CVE-2024-29925 Moyenne · 6,4
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Post Grid, Slider & Carousel Ultimate <= 1.6.6 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Post Grid, Slider & Carousel Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-1.6.6

Correctif

1.6.7

Publication

25/03/2024

CVE-2024-2006 Élevée · 8,8
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.7 – Authenticated (Contributor+) PHP Object Injection in outpost_shortcode_metabox_markup

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.7 via deserialization of untrusted input in…

Versions affectées

*-1.6.7

Correctif

1.6.8

Publication

05/03/2024

Vulnérabilité Moyenne · 4,3
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Appsero <= 1.2.1 – Missing Authorization

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible…

Versions affectées

*-1.6.3

Correctif

1.6.4

Publication

16/12/2022

CVE-2022-47150 Moyenne · 4,3
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Appsero <= 1.2.0 – Cross-Site Request Forgery

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it…

Versions affectées

*-1.6.3

Correctif

1.6.4

Publication

14/12/2022

CVE-2022-1266 Moyenne · 5,5
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Post Grid, Slider & Carousel Ultimate <= 1.4.3 – Authenticated (Admin+) Cross-Site Scripting

The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Versions affectées

[*, 1.5.0)

Correctif

1.5.0

Publication

26/05/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités