PatchSiren

pickplugins CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL pickplugins CVE published 2026-09-05

CVE-2024-11080

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress, granted no other security controls are present in the function. The issue is located in several functions within the ~/includes/blocks/form-wrap/function.php file. [truncated]

HIGH PickPlugins CVE published 2026-08-19

CVE-2026-14861

The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.

MEDIUM pickplugins CVE published 2026-06-09

CVE-2026-10862

The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all versions up to, and including, 2.3.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

MEDIUM PickPlugins CVE published 2026-05-25

CVE-2025-62745

A stored cross-site scripting (XSS) vulnerability exists in the Team Showcase WordPress plugin by PickPlugins, affecting versions up to and including 1.22.28. The flaw stems from improper neutralization of input during web page generation (CWE-79), allowing authenticated attackers with low privileges to inject malicious scripts that execute in victims' browsers. The vulnerability was published to the CVE [truncated]