Pixelgrade develops a suite of WordPress plugins and themes focused on site customization and content-handling functionality, positioning them across a modestly represented but more-prominent-than-typical share of the WordPress ecosystem. The vendor's vulnerability exposure recurs through web-application input-handling weaknesses, chiefly cross-site request forgery and cross-site scripting flaws that reflect the challenges of managing user input and state in plugin contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pixelgrade over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24528MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Blocks nova-blocks allows DOM-Based XSS.This issue affects Nov | Jan 23, 2026 | 6.5 | 25 | NO | NO |
CVE-2023-27633HIGH Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Customify – Intuitive Website Styling plugin <= 2.10.4 versions. | Nov 22, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-25487HIGH Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade PixTypes plugin <= 1.4.14 versions. | Jul 11, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-23704HIGH Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.6 versions. | Jul 11, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-45655HIGH Cross-Site Request Forgery (CSRF) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions. | Oct 16, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-45654HIGH Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions. | Oct 16, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-4671MEDIUM The PixCodes WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a rol | Jan 30, 2023 | 5.4 | 21 | NO | NO |
CVE-2022-46844MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions. | May 9, 2023 | 5.4 | 20 | NO | NO |
CVE-2025-31819MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Blocks nova-blocks.This issue affects Nova Blocks: from n/a th | Apr 1, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-8241MEDIUM The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute of the 'wp:separator' Gutenberg block in all versions up t | Sep 10, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pixelgrade.
Media articles that mention a CVE ID that affects a product developed by Pixelgrade — matched by CVE ID, not by vendor name.