Show filters
79 Total Results
Displaying 71-79 of 79
Sort by:
Attacker Value
Unknown
CVE-2021-24652
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.
0
Attacker Value
Unknown
CVE-2021-24661
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID.
0
Attacker Value
Unknown
CVE-2021-24659
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.
0
Attacker Value
Unknown
CVE-2021-24660
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.
0
Attacker Value
Unknown
CVE-2021-24488
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2020-35936
Disclosure Date: January 01, 2021 (last updated February 22, 2025)
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.
0
Attacker Value
Unknown
CVE-2020-35938
Disclosure Date: January 01, 2021 (last updated February 22, 2025)
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.
0
Attacker Value
Unknown
CVE-2020-35937
Disclosure Date: January 01, 2021 (last updated February 22, 2025)
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.
0
Attacker Value
Unknown
CVE-2020-35939
Disclosure Date: January 01, 2021 (last updated February 22, 2025)
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.
0