Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pickplugins

First CVE: May 28, 2020Active for: 6 yearsTotal CVEs: 44
34.4
VTI Score
Medium

Pickplugins develops a focused portfolio of WordPress plugins centered on content display and e-commerce functionality, including products such as Post Grid, Team Showcase, and ComboBlocks that serve web publishers and online retailers. The vendor's vulnerability footprint is modestly represented in the landscape but sits within a more prominent tier, reflecting the broad WordPress ecosystem's exposure surface. Weaknesses recurring across these plugins cluster around cross-site scripting and input-handling flaws endemic to server-side template and form processing, alongside deserialization and sensitive-information disclosure patterns typical of plugins that handle user data and database queries. Public exploit code becomes available with some regularity for this vendor's disclosures, consistent with the appeal of widely installed WordPress plugins as targets for automated scanning and payload delivery. Defenders should apply this vendor's patches promptly to internet-facing WordPress instances and monitor plugin dependencies for supply-chain risk; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
44
Total CVEs
More Total CVEs than 98% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pickplugins over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 28, 2020
6 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (44 CVEs).

44 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24488MEDIUM
The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading
Aug 2, 20216.143NOYES
CVE-2021-24300MEDIUM
The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to
May 24, 20216.143NOYES
CVE-2024-0881MEDIUM
The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password pro
Apr 11, 20245.433NOYES
CVE-2023-40211HIGH
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Bl
Nov 30, 20237.532NOYES
CVE-2022-4693CRITICAL
The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depe
Jan 23, 20239.831NONO
CVE-2024-8253HIGH
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting w
Sep 11, 20248.829NONO
CVE-2020-35939HIGH
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure u
Jan 1, 20218.827NONO
CVE-2020-35938HIGH
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unseri
Jan 1, 20218.827NONO
CVE-2021-4450HIGH
The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and including, 2.1.12 due to insufficient escaping on the user supplied
Oct 16, 20248.826NONO
CVE-2025-32143HIGH
Deserialization of Untrusted Data vulnerability in PickPlugins Accordion accordions allows Object Injection.This issue affects Accordion: from n/a through <= 2.3.11.
Apr 11, 20258.825NONO
View all 44 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products44 CVEs
64%
34%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network44 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (97.7%)
High1 (2.3%)
Unknown0 (0.0%)
User Interaction
None22 (50.0%)
Unknown0 (0.0%)
Required22 (50.0%)
Privileges Required
Low30 (68.2%)
High0 (0.0%)
None14 (31.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (44 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
9.1% of CVEs· 96th percentile
ExploitDB
2 CVEs
4.5% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pickplugins.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pickplugins — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pickplugins's Products

View all 4 CNAs →

Top CWEs