Extension WordPress
Vulnérabilités Post Grid, page 2
Cette page rassemble les failles publiées pour Post Grid, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Post Grid
29 fiches
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel <= 2.2.74 – Information Exposure
The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.74 via the post_grid_paginate_ajax_free AJAX endpoint. This makes it…
*-2.2.74
2.2.76
19/03/2024
Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 – Information Exposure via get_posts API Endpoint
The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 via the 'get_posts' REST API Endpoint. This makes it possible for unauthenticated attackers…
*-2.2.68
2.2.69
12/03/2024
Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.64 – Authenticated (Contributor+) Cross-Site Scripting
The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.2.64 due to insufficient input sanitization and output escaping.…
*-2.2.64
2.2.65
15/12/2023
Post Grid <= 2.2.50 – Missing Authorization to Sensitive Information Exposure via REST API
The Post Grid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple REST API endpoints in versions up to, and including, 2.2.50. This makes it possible for unauthenticated attackers…
*-2.2.50
2.2.51
11/08/2023
Post Grid < 2.1.16 – Reflected Cross-Site Scripting
The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting
[*, 2.1.16)
2.1.16
15/03/2022
Post Grid <= 2.1.15 – Cross-Site Scripting
The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form
[*, 2.1.16)
2.1.16
15/03/2022
Post Grid <= 2.1.12 – Contributor+ SQL Injection
The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
[*, 2.1.13)
2.1.13
15/12/2021
Post Grid <= 2.1.7 – Reflected Cross-Site Scripting
The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues
*-2.1.7
2.1.8
28/06/2021
Post Grid <= 2.0.12 – Arbitrary File Deletion
The Post Grid plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.0.12. This is due to the plugin failing to properly verify user input. This makes it possible for unauthenticated attackers…
*-2.0.12
2.0.13
08/11/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.