Essential Grid Portfolio – Photo Gallery [essential-grid] < 3.0.19 (closed)
unknown
[en] Missing Authorization vulnerability in ThemePunch OHG Essential Grid.This issue affects Essential Grid: from n/a through 3.0.18.
- Affected:
- up to 3.0.19
- Fixed in:
- 3.0.19
- Disclosed:
- Jun 19, 2024
CVE-2023-47771 on NVD →
Essential Grid <= 3.1.1 - Unauthenticated Private Post Disclosure
medium
The Essential Grid Gallery WordPress Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.1 via the on_front_ajax_action() function. This makes it possible for unauthenticated attackers to view private and password protected posts that may have private or...
- CVSS:
- 5.3
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.2
- Disclosed:
- Apr 9, 2024
CVE-2024-3235 on NVD →
Essential Grid <= 3.0.18 - Missing Authorization
high
The Essential Grid plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in versions up to, and including, 3.0.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to access those functions intended fo...
- CVSS:
- 8.3
- Affected:
- up to 3.0.18
- Fixed in:
- 3.0.19
- Disclosed:
- Nov 14, 2023
CVE-2023-47771 on NVD →
Essential Grid Portfolio – Photo Gallery [essential-grid] < 3.1.1 (closed)
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThemePunch OHG Essential Grid plugin <= 3.1.0 versions.
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- Nov 13, 2023
CVE-2023-47684 on NVD →
Essential Grid <= 3.1.0 - Reflected Cross-Site Scripting
medium
The Essential Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...
- CVSS:
- 6.1
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.1
- Disclosed:
- Nov 9, 2023
CVE-2023-47684 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database