Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection
high
The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it possible for authenticated attackers, with Ad...
- CVSS:
- 7.2
- Affected:
- up to 3.0.12
- Fixed in:
- 3.0.13
- Disclosed:
- Apr 13, 2026
CVE-2026-3017 on NVD →
Smart Post Show <= 3.0.0 - Authenticated (Editor+) Stored Cross-Site Scripting via Pagination Color
medium
The Smart Post Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pagination Color setting in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary...
- CVSS:
- 5.5
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.1
- Disclosed:
- Oct 8, 2024
CVE-2024-8187 on NVD →
Post Grid, Post Carousel, & List Category Posts <= 2.4.27 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.27 due to insufficient input...
- CVSS:
- 4.4
- Affected:
- up to 2.4.27
- Fixed in:
- 2.4.28
- Disclosed:
- Apr 4, 2024
CVE-2024-3996 on NVD →
Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More [post-carousel] < 2.4.19
unknown
[en] The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 2.4.19
- Fixed in:
- 2.4.19
- Disclosed:
- Jan 30, 2023
CVE-2023-0097 on NVD →
Post Grid, Post Carousel, & List Category Posts <= 2.4.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Post Grid, Post Carousel, & List Category Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...
- CVSS:
- 6.4
- Affected:
- up to 2.4.18
- Fixed in:
- 2.4.19
- Disclosed:
- Jan 6, 2023
CVE-2023-0097 on NVD →
Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More [post-carousel] < 2.3.5
unknown
Update the WordPress Post Grid, Post Carousel, & List Category Posts – by Smart Post Show plugin to the latest available version (at least 2.3.5).
WPScan discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Post Grid, Post Carousel, & List Category Posts – by Smart Post Show Plugin....
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.5
- Disclosed:
- Jan 6, 2023
Post Carousel < 2.3.5 - Missing Capabilities Check
high
The Post Carousel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on multiple functions in versions up to, and including, 2.3.4. This makes it possible for attackers to improperly access administrative actions.
- CVSS:
- 7.3
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.5
- Disclosed:
- Aug 16, 2021
Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More [post-carousel] < 2.3.5
unknown
The Post Carousel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on multiple functions in versions up to, and including, 2.3.4. This makes it possible for attackers to improperly access administrative actions.
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.5
- Disclosed:
- Aug 16, 2021
Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More [post-carousel] < 2.3.5
unknown
The plugin did not properly check for CSRF in two of its AJAX actions, allowing them to be bypassed. Furthermore, other actions which should only be accessible to admins were missing capability check (but had CSRF checks), and the spf-reset action did not validate that the actions to be delete belong to the plugin. Var...
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.5
Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More [post-carousel] < 2.4.28
unknown
- Affected:
- up to 2.4.28
- Fixed in:
- 2.4.28
CVE-2024-3996 on NVD →
Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More [post-carousel] < 3.0.1
unknown
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
CVE-2024-8187 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database