WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout [gs-pinterest-portfolio] < 1.6.8
unknown
[en] Missing Authorization vulnerability in GS Plugins GS Pins for Pinterest allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GS Pins for Pinterest: from n/a through 1.6.7.
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.8
- Disclosed:
- Dec 13, 2024
CVE-2023-32593 on NVD →
WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout [gs-pinterest-portfolio] < 1.8.9
unknown
[en] The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gs_pin_widget' shortcode in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping on user supplie...
- Affected:
- up to 1.8.9
- Fixed in:
- 1.8.9
- Disclosed:
- Dec 3, 2024
CVE-2024-11453 on NVD →
WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout <= 1.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gs_pin_widget' shortcode in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping on user supplied att...
- CVSS:
- 6.4
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.9
- Disclosed:
- Dec 2, 2024
CVE-2024-11453 on NVD →
WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout [gs-pinterest-portfolio] < 1.8.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Pins for Pinterest allows Stored XSS.This issue affects GS Pins for Pinterest: from n/a through 1.8.2.
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.3
- Disclosed:
- Mar 27, 2024
CVE-2024-30192 on NVD →
GS Pins for Pinterest <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shorcode
medium
The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This ma...
- CVSS:
- 6.4
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.3
- Disclosed:
- Mar 25, 2024
CVE-2024-30192 on NVD →
WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout [gs-pinterest-portfolio] < 1.8.1
unknown
Update the WordPress GS Pins for Pinterest plugin to the latest available version (at least 1.8.1).
Unknown discovered and reported this Broken Access Control vulnerability in WordPress GS Pins for Pinterest Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in...
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Nov 22, 2023
GS Pins for Pinterest Lite <= 1.8.0 - Missing Authorization via _update_shortcode
medium
The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a misconfigured nonce check on the _update_shortcode function in all versions up to and including 1.8.0. This makes it pos...
- CVSS:
- 4.3
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Nov 21, 2023
WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout [gs-pinterest-portfolio] < 1.8.1
unknown
The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a misconfigured nonce check on the _update_shortcode function in all versions up to and including 1.8.0. This makes it pos...
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Nov 21, 2023
WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout [gs-pinterest-portfolio] < 1.6.2
unknown
Update the WordPress GS Pins for Pinterest plugin to the latest available version (at least 1.6.2).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress GS Pins for Pinterest Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements,...
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- Mar 27, 2023
WordPress Pinterest Plugin <= 1.6.1 - Stored (Contributor+) Cross-Site Scripting via Shortcode
medium
The WordPress Pinterest Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gs_pinterest' shortcode in versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-...
- CVSS:
- 6.4
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.2
- Disclosed:
- Mar 22, 2023
WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout [gs-pinterest-portfolio] < 1.6.2
unknown
The WordPress Pinterest Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gs_pinterest' shortcode in versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-...
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- Mar 22, 2023
Appsero <= 1.2.1 - Missing Authorization
medium
The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...
- CVSS:
- 4.3
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.3
- Disclosed:
- Dec 16, 2022
Appsero <= 1.2.0 - Cross-Site Request Forgery
medium
The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...
- CVSS:
- 4.3
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.3
- Disclosed:
- Dec 14, 2022
CVE-2022-47150 on NVD →
WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout [gs-pinterest-portfolio] < 1.6.3
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
CVE-2022-47150 on NVD →
WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout [gs-pinterest-portfolio] < 1.8.1
unknown
The plugin is vulnerable to unauthorized modification of data due to a missing capability check and a misconfigured nonce check on the _update_shortcode function, allowing authenticated attackers, with subscriber access and above, to update the plugin's shortcodes.
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database