Pickplugins develops a focused portfolio of WordPress plugins centered on content display and e-commerce functionality, including products such as Post Grid, Team Showcase, and ComboBlocks that serve web publishers and online retailers. The vendor's vulnerability footprint is modestly represented in the landscape but sits within a more prominent tier, reflecting the broad WordPress ecosystem's exposure surface. Weaknesses recurring across these plugins cluster around cross-site scripting and input-handling flaws endemic to server-side template and form processing, alongside deserialization and sensitive-information disclosure patterns typical of plugins that handle user data and database queries. Public exploit code becomes available with some regularity for this vendor's disclosures, consistent with the appeal of widely installed WordPress plugins as targets for automated scanning and payload delivery. Defenders should apply this vendor's patches promptly to internet-facing WordPress instances and monitor plugin dependencies for supply-chain risk; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pickplugins over time
Signals from CVEs in this vendor scope (44 CVEs).
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24488MEDIUM The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading | Aug 2, 2021 | 6.1 | 43 | NO | YES |
CVE-2021-24300MEDIUM The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to | May 24, 2021 | 6.1 | 43 | NO | YES |
CVE-2024-0881MEDIUM The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password pro | Apr 11, 2024 | 5.4 | 33 | NO | YES |
CVE-2023-40211HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Bl | Nov 30, 2023 | 7.5 | 32 | NO | YES |
CVE-2022-4693CRITICAL The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depe | Jan 23, 2023 | 9.8 | 31 | NO | NO |
CVE-2024-8253HIGH The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting w | Sep 11, 2024 | 8.8 | 29 | NO | NO |
CVE-2020-35939HIGH PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure u | Jan 1, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-35938HIGH PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unseri | Jan 1, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-4450HIGH The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied | Oct 16, 2024 | 8.8 | 26 | NO | NO |
CVE-2025-32143HIGH Deserialization of Untrusted Data vulnerability in PickPlugins Accordion accordions allows Object Injection.This issue affects Accordion: from n/a through <= 2.3.11. | Apr 11, 2025 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (44 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pickplugins.
Media articles that mention a CVE ID that affects a product developed by Pickplugins — matched by CVE ID, not by vendor name.