| CVE-2024-38726 | WordPress Product Designer plugin <= 1.0.33 - Arbitrary Content Deletion vulnerability | PickPlugins | Product Designer | High | 7.5 | 2024-11-01 14:18:05 | Deep Dive |
| CVE-2024-50432 | WordPress Post Grid and Gutenberg Blocks plugin <= 2.2.93 - Cross Site Scripting (XSS) vulnerability | PickPlugins | Post Grid and Gutenberg Blocks | Medium | 6.5 | 2024-10-28 18:17:12 | Deep Dive |
| CVE-2021-4450 | Post Grid <= 2.1.12 - Contributor+ SQL Injection | pickplugins | Post Grid | High | 8.8 | 2024-10-16 06:43:38 | Deep Dive |
| CVE-2024-47340 | WordPress ComboBlocks plugin <= 2.2.89 - Cross Site Scripting (XSS) vulnerability | PickPlugins | Post Grid and Gutenberg Blocks | Medium | 6.5 | 2024-10-06 10:51:25 | Deep Dive |
| CVE-2024-47342 | WordPress Accordion plugin <= 2.2.99 - Cross Site Scripting (XSS) vulnerability | PickPlugins | Accordion | Medium | 6.5 | 2024-10-06 10:48:09 | Deep Dive |
| CVE-2024-44002 | WordPress Team Showcase plugin <= 1.22.25 - Reflected Cross Site Scripting (XSS) vulnerability | PickPlugins | Team Showcase | High | 7.1 | 2024-09-17 23:12:03 | Deep Dive |
| CVE-2024-45459 | WordPress Product Slider for WooCommerce by PickPlugins plugin <= 1.13.50 - Reflected Cross Site Scripting (XSS) vulnerability | PickPlugins | Product Slider for WooCommerce | High | 7.1 | 2024-09-15 07:41:38 | Deep Dive |
| CVE-2024-8253 | Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation | pickplugins | Post Grid and Gutenberg Blocks | High | 8.8 | 2024-09-11 03:31:08 | Deep Dive |
| CVE-2024-43321 | WordPress Team Showcase plugin <= 1.22.23 - Cross Site Scripting (XSS) vulnerability | PickPlugins | Team Showcase | Medium | 6.5 | 2024-08-18 14:13:55 | Deep Dive |
| CVE-2024-7588 | Gutenberg Blocks, Page Builder – ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block | pickplugins | Post Grid | Medium | 6.4 | 2024-08-14 04:29:55 | Deep Dive |
| CVE-2024-43155 | WordPress ComboBlocks plugin <= 2.2.86 - Cross Site Scripting (XSS) vulnerability | PickPlugins | ComboBlocks | Medium | 6.5 | 2024-08-12 22:06:59 | Deep Dive |
| CVE-2024-6346 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget | pickplugins | Post Grid | Medium | 6.4 | 2024-08-01 09:29:48 | Deep Dive |
| CVE-2024-38722 | WordPress Job Board Manager plugin <= 2.1.57 - Cross Site Scripting (XSS) vulnerability | PickPlugins | Job Board Manager | Medium | 6.5 | 2024-07-20 07:21:18 | Deep Dive |
| CVE-2024-3608 | Product Designer <= 1.0.33 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion | pickplugins | PickPlugins Product Designer for WooCommerce | Medium | 5.3 | 2024-07-09 08:33:04 | Deep Dive |
| CVE-2024-4042 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute | pickplugins | Post Grid | Medium | 6.4 | 2024-06-07 05:33:45 | Deep Dive |
| CVE-2024-1988 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting | pickplugins | Post Grid | Medium | 6.4 | 2024-06-07 03:21:58 | Deep Dive |
| CVE-2023-40557 | WordPress Tabs & Accordion plugin <= 1.3.10 - Content Injection vulnerability | PickPlugins | Tabs & Accordion | Medium | 5.4 | 2024-06-04 07:20:12 | Deep Dive |
| CVE-2024-3155 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting | pickplugins | Post Grid | Medium | 6.4 | 2024-05-21 02:32:59 | Deep Dive |
| CVE-2024-32816 | WordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerability | PickPlugins | Post Grid | High | 7.5 | 2024-04-24 07:41:32 | Deep Dive |
| CVE-2024-1641 | Accordion <= 2.2.96 - Missing Authorization to Authenticated(Contributor+) Post Duplication | pickplugins | Accordions | Medium | 5.4 | 2024-04-09 18:58:32 | Deep Dive |