Pickplugins Pickplugins

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Pickplugins product.

RSS Feeds for Pickplugins security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Pickplugins products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Pickplugins Sorted by Most Security Vulnerabilities since 2018

Pickplugins Post Grid23 vulnerabilities

Pickplugins Accordion6 vulnerabilities

Pickplugins Post Grid Combo5 vulnerabilities

Pickplugins Wishlist4 vulnerabilities

Pickplugins Comboblocks4 vulnerabilities

Pickplugins Testimonial3 vulnerabilities

Pickplugins Mail Picker2 vulnerabilities

Pickplugins Team2 vulnerabilities

Pickplugins Team Showcase1 vulnerability

Pickplugins Related Post1 vulnerability

Pickplugins Pricing Table1 vulnerability

Pickplugins Breadcrumb1 vulnerability

By the Year

In 2026 there have been 6 vulnerabilities in Pickplugins with an average score of 6.8 out of ten. Last year, in 2025 Pickplugins had 25 security vulnerabilities published. Right now, Pickplugins is on track to have less security vulnerabilities in 2026 than it did last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.12.




Year Vulnerabilities Average Score
2026 6 6.83
2025 25 6.72
2024 26 6.73
2023 4 7.03
2022 2 6.25
2021 3 5.87

It may take a day or so for new Pickplugins vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Pickplugins Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-10862 Jun 09, 2026
WordPress Accordions Plugin <=2.3.23 Stored XSS via Accordion Body The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all versions up to, and including, 2.3.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Accordion
CVE-2025-62745 May 25, 2026
Team Showcase <=1.22.28 Stored XSS in PickPlugins Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. This issue affects Team Showcase: from n/a through 1.22.28.
Team
CVE-2026-7458 May 02, 2026
WordPress PickPlugins User Verification 2.0.46 Auth Bypass via Loose PHP compare The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting a "true" OTP value.
User Verification
CVE-2026-32497 Mar 25, 2026
PickPlugins User Verification <=2.0.45 Weak Authentication (Auth Abuse) Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This issue affects User Verification: from n/a through <= 2.0.45.
User Verification
CVE-2026-25455 Mar 25, 2026
Missing Auth in PickPlugins Product Slider WooCommerce <=1.13.60 Missing Authorization vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Slider for WooCommerce: from n/a through <= 1.13.61.
Product Slider For Woocommerce
CVE-2025-68000 Feb 20, 2026
Missing Auth in PickPlugins Testimonial Slider 2.0.15 via ACL Missing Authorization vulnerability in PickPlugins Testimonial Slider testimonial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Testimonial Slider: from n/a through <= 2.0.15.
Testimonial
CVE-2025-68605 Dec 24, 2025
Stored XSS in Post Grid & Gutenberg Blocks <=2.3.18 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23.
Post Grid
CVE-2025-63043 Dec 18, 2025
Auth Bypass via UserControlled Key in PickPlugins PGGB 2.3.19 Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.3.19.
Post Grid
CVE-2025-66058 Dec 18, 2025
Missing Auth in PickPlugins Post Grid/Gutenberg Blocks 2.3.17 Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.3.17.
Post Grid
CVE-2025-12374 Dec 05, 2025
Auth Bypass in WordPress User Verification Plugin <=2.0.39 The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login User Verification plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.39. This is due to the plugin not properly validating that an OTP was generated before comparing it to user input in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting an empty OTP value.
CVE-2025-62929 Oct 27, 2025
Missing Auth in PickPlugins Testimonial Slider <=2.0.15 Missing Authorization vulnerability in PickPlugins Testimonial Slider testimonial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Testimonial Slider: from n/a through <= 2.0.15.
Testimonial
CVE-2025-62924 Oct 27, 2025
Missing Auth in Post Grid & Gutenberg Blocks (<=2.3.17) Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.17.
Post Grid
CVE-2025-53421 Oct 22, 2025
PickPlugins Accordion Missing Authorization (<=2.3.14) Missing Authorization vulnerability in PickPlugins Accordion accordions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion: from n/a through <= 2.3.14.
Accordion
CVE-2025-60162 Sep 26, 2025
PickPlugins Job Board Manager <2.1.61 DOM XSS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager allows DOM-Based XSS. This issue affects Job Board Manager: from n/a through 2.1.61.
CVE-2025-58678 Sep 22, 2025
Missing Auth in PickPlugins Accordion v2.3.14 Missing Authorization vulnerability in PickPlugins Accordion allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Accordion: from n/a through 2.3.14.
CVE-2025-54007 Aug 20, 2025
Deserialization of Untrusted Data in Post Grid & Gutenberg Blocks 2.3.11 Deserialization of Untrusted Data vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Object Injection.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.11.
Post Grid
CVE-2024-9645 May 15, 2025
WP Plugin 'The Post Grid' <2.2.93 XSS via unescaped block options (Contributor+) The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Post Grid
CVE-2025-24655 Apr 17, 2025
PickPlugins Wishlist XSS via Reflected Input (<=1.0.39) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Wishlist wishlist allows Reflected XSS.This issue affects Wishlist: from n/a through <= 1.0.39.
Wishlist
CVE-2025-32618 Apr 11, 2025
SQLI in PickPlugins Wishlist (1.0.43+) via Improper Input Validation Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist wishlist allows SQL Injection.This issue affects Wishlist: from n/a through <= 1.0.46.
Wishlist
CVE-2025-32143 Apr 11, 2025
Deserialization CVE-2025-32143: Object Injection in PickPlugins Accordion <=2.3.10 Deserialization of Untrusted Data vulnerability in PickPlugins Accordion accordions allows Object Injection.This issue affects Accordion: from n/a through <= 2.3.11.
Accordion
CVE-2025-32144 Apr 11, 2025
Job Board Manager 2.1.60 Deserialization Vulnerability (Object Injection) Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager job-board-manager allows Object Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61.
Job Board Manager
CVE-2025-30889 Apr 03, 2025
Deserialization Untrusted Data in PickPlugins Testimonial Slider < 2.0.13 Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider testimonial allows Object Injection.This issue affects Testimonial Slider: from n/a through <= 2.0.13.
Testimonial
CVE-2025-31810 Apr 01, 2025
PickPlugins Q&A v<1.2.71 Missing Auth ACL Issue Missing Authorization vulnerability in PickPlugins Question Answer question-answer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Question Answer: from n/a through <= 1.2.73.
Question Answer
CVE-2025-31862 Apr 01, 2025
Missing Auth in PickPlugins Job Board Manager <=2.1.60 Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.61.
Job Board Manager
CVE-2024-12809 Mar 07, 2025
Stored XSS via wishlist_button Shortcode in Wishlist Plugin <=1.0.43 The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortcode in all versions up to, and including, 1.0.43 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Wishlist
CVE-2024-13469 Feb 28, 2025
Stored XSS via Button Link in PickPlugins PricingTable WP Plugin <=1.12.10 The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link in all versions up to, and including, 1.12.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Pricing Table
CVE-2024-13796 Feb 28, 2025
ComboBlocks <=2.3.6 SI Exposure via /wp-json/get_users The Post Grid and Gutenberg Blocks ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.6 via the /wp-json/post-grid/v2/get_users REST API This makes it possible for unauthenticated attackers to extract sensitive data including including emails and other user data.
Post Grid
CVE-2025-26915 Feb 25, 2025
SQLi in PickPlugins Wishlist <=1.0.41 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist wishlist allows SQL Injection.This issue affects Wishlist: from n/a through <= 1.0.41.
Wishlist
CVE-2024-13798 Feb 22, 2025
ComboBlocks WP Plugin 2.3.5 Unauth Order Creation The Post Grid and Gutenberg Blocks ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. This is due to insufficient verification on form fields. This makes it possible for unauthenticated attackers to create new orders for products and mark them as paid without actually completing a payment.
Comboblocks
Post Grid
CVE-2025-24622 Jan 24, 2025
CSRF in PickPlugins Job Board Manager v<=2.1.59 Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Job Board Manager job-board-manager allows Cross Site Request Forgery.This issue affects Job Board Manager: from n/a through <= 2.1.59.
Job Board Manager
CVE-2024-13408 Jan 24, 2025
Post Grid Slider Carousel Ultimate LFI via pgcu shortcode (<=1.6.10) The Post Grid, Slider & Carousel Ultimate with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 via the 'theme' attribute of the `pgcu` shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php files can be uploaded and included.
Post Grid
CVE-2024-55993 Dec 16, 2024
Missing Auth in PickPlugins JBM <=2.1.60 Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.61.
Job Board Manager
CVE-2024-54273 Dec 13, 2024
Mail Picker <1.0.14: Deserialization Obj Injection via PickPlugins Deserialization of Untrusted Data vulnerability in PickPlugins Mail Picker mail-picker allows Object Injection.This issue affects Mail Picker: from n/a through <= 1.0.14.
Mail Picker
CVE-2024-10937 Dec 05, 2024
WordPress PickPlugins Related Posts Plugin SI Exposure 2.0.58 The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_related_post_ajax_get_post_ids AJAX action. This makes it possible for unauthenticated attackers to extract sensitive data including titles of posts in draft status.
Post Grid Combo
CVE-2024-53772 Nov 30, 2024
Mail Picker <=1.0.14 DOM XSS via input neutralization (PickPlugins) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Mail Picker mail-picker allows DOM-Based XSS.This issue affects Mail Picker: from n/a through <= 1.0.15.
Mail Picker
CVE-2024-9111 Nov 21, 2024
WordPress Product Designer Plugin: Stored XSS via SVG File Uploads The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
CVE-2024-50432 Oct 28, 2024
XSS in PickPlugins Post Grid & Gutenberg Blocks <=2.2.93 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Cross-Site Scripting (XSS).This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.2.93.
Post Grid
CVE-2021-4450 Oct 16, 2024
Post Grid WP Plugin v2.1.12 Blind SQLi via Post Meta The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level permissions and above to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Post Grid
CVE-2024-47340 Oct 06, 2024
PickPlugins Post Grid/XSS in 2.2.89 and earlier Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.2.89.
Post Grid
CVE-2024-47342 Oct 06, 2024
PickPlugins Accordion <=2.2.99 XSS (Stored) Vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Accordion accordions allows Stored XSS.This issue affects Accordion: from n/a through <= 2.2.99.
Accordion
CVE-2024-44002 Sep 18, 2024
Reflected XSS in PickPlugins Team Showcase <=1.22.25 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase team allows Reflected XSS.This issue affects Team Showcase: from n/a through <= 1.22.25.
Team Showcase
Team
CVE-2024-45459 Sep 15, 2024
Reflected XSS in PickPlugins Product Slider for WooCommerce 1.13.50 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Reflected XSS.This issue affects Product Slider for WooCommerce: from n/a through <= 1.13.50.
Product Slider For Woocommerce
CVE-2024-8253 Sep 11, 2024
Post Grid & Gutenberg Blocks 2.2.90 Priv Esc via User Meta Update The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting what user meta values can be updated and ensuring a form is active. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their user meta to become an administrator.
Post Grid
CVE-2024-7588 Aug 14, 2024
WordPress ComboBlocks Stored XSS via AccBlock (2.2.87) The Gutenberg Blocks, Page Builder ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion block in all versions up to, and including, 2.2.87 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Page Builder Comboblocks
CVE-2024-43155 Aug 12, 2024
PickPlugins ComboBlocks <=2.2.86 Stored XSS via improper input neutralization Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins ComboBlocks allows Stored XSS.This issue affects ComboBlocks: from n/a through 2.2.86.
Comboblocks
CVE-2024-6346 Aug 01, 2024
Stored XSS in ComboBlocks v2.2.85a via redirectURL in Date Countdown The Gutenberg Blocks, Page Builder ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the redirectURL parameter of the Date Countdown widget, in all versions up to, and including, 2.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Comboblocks
Post Grid
CVE-2024-3608 Jul 09, 2024
Product Designer <=1.0.33 WP Plugin Attach Delete Flaw (CVE-2024-3608) The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to delete arbitrary attachments. CVE-2024-38726 appears to be a duplicate of this issue.
Product Designer
CVE-2024-4042 Jun 07, 2024
Combo Blocks WP Plugin XSS via class attribute ( 2.2.80) The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the menu-wrap-item block in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Comboblocks
Post Grid
CVE-2024-1988 Jun 07, 2024
Combo Blocks WP Plugin 2.2.80 Stored XSS in 'tag' Attribute The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute in blocks in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Post Grid
CVE-2024-3155 May 21, 2024
Combo Blocks Plugin <=2.2.80 XSS via params The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Post Grid Combo
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.