MEDIUM🇵🇱 Wersja polska

CVE-2023-6645

CVSS 6.4v3.1pub. 2024-01-11upd. 2026-04-08

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.2.64 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
  • Pickplugins Post Grid Combo

    APP
    Pickplugins
    ≤ 2.2.64
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2023-7072HIGH7.5same product

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposur...

CVE-2023-40211HIGH7.5same product

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ ...

CVE-2022-4693CRITICAL9.8PL ✓same vendor

Auth Bypass w wtyczce User Verification dla WordPress

CVE-2024-13408HIGH7.5same vendor

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for Word...

CVE-2021-4450HIGH8.8same vendor

The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, a...