RSS   Vulnerabilities for 'Post grid'   RSS

2022-04-11
 
CVE-2021-24986

CWE-79
 

 
The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form

 
 
CVE-2022-0447

CWE-79
 

 
The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting

 
2021-08-02
 
CVE-2021-24488

CWE-79
 

 
The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues

 

 >>> Vendor: Pickplugins 3 Products
Accordion
Product slider for woocommerce
Post grid


Copyright 2024, cxsecurity.com

 

Back to Top