plugin

Essential Grid Vulnerabilities

5 known security issues reported for the Essential Grid WordPress plugin. Most recent disclosed Jun 19, 2024.

1 high 2 medium

Running Essential Grid on your site? Check whether your installed version is affected.

Scan your site free

Essential Grid Portfolio – Photo Gallery [essential-grid] < 3.0.19 (closed)

unknown

[en] Missing Authorization vulnerability in ThemePunch OHG Essential Grid.This issue affects Essential Grid: from n/a through 3.0.18.

Affected:
up to 3.0.19
Fixed in:
3.0.19
Disclosed:
Jun 19, 2024

CVE-2023-47771 on NVD →

Essential Grid <= 3.1.1 - Unauthenticated Private Post Disclosure

medium

The Essential Grid Gallery WordPress Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.1 via the on_front_ajax_action() function. This makes it possible for unauthenticated attackers to view private and password protected posts that may have private or...

CVSS:
5.3
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
Apr 9, 2024

CVE-2024-3235 on NVD →

Essential Grid <= 3.0.18 - Missing Authorization

high

The Essential Grid plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in versions up to, and including, 3.0.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to access those functions intended fo...

CVSS:
8.3
Affected:
up to 3.0.18
Fixed in:
3.0.19
Disclosed:
Nov 14, 2023

CVE-2023-47771 on NVD →

Essential Grid Portfolio – Photo Gallery [essential-grid] < 3.1.1 (closed)

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThemePunch OHG Essential Grid plugin <= 3.1.0 versions.

Affected:
up to 3.1.1
Fixed in:
3.1.1
Disclosed:
Nov 13, 2023

CVE-2023-47684 on NVD →

Essential Grid <= 3.1.0 - Reflected Cross-Site Scripting

medium

The Essential Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...

CVSS:
6.1
Affected:
up to 3.1.0
Fixed in:
3.1.1
Disclosed:
Nov 9, 2023

CVE-2023-47684 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database