Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins [related-post] < 2.0.60
unknown
[en] The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 2.0.59. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers...
- Affected:
- up to 2.0.60
- Fixed in:
- 2.0.60
- Disclosed:
- Mar 7, 2025
CVE-2024-12634 on NVD →
Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.59 - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 2.0.59. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to i...
- CVSS:
- 6.1
- Affected:
- 2.0.59 – 2.0.59
- Fixed in:
- 2.0.60
- Disclosed:
- Mar 6, 2025
CVE-2024-12634 on NVD →
Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins [related-post] < 2.0.59
unknown
[en] The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_related_post_ajax_get_post_ids AJAX action. This makes it possible for unauthent...
- Affected:
- up to 2.0.59
- Fixed in:
- 2.0.59
- Disclosed:
- Dec 5, 2024
CVE-2024-10937 on NVD →
Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.58 - Sensitive Information Exposure
medium
The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_related_post_ajax_get_post_ids AJAX action. This makes it possible for unauthenticate...
- CVSS:
- 5.3
- Affected:
- up to 2.0.58
- Fixed in:
- 2.0.59
- Disclosed:
- Dec 4, 2024
CVE-2024-10937 on NVD →
Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins [related-post] < 2.0.54
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Related Post allows Stored XSS.This issue affects Related Post: from n/a through 2.0.53.
- Affected:
- up to 2.0.54
- Fixed in:
- 2.0.54
- Disclosed:
- Feb 1, 2024
CVE-2023-51666 on NVD →
Related Post <= 2.0.53 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Related Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.0.53 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level...
- CVSS:
- 6.4
- Affected:
- up to 2.0.53
- Fixed in:
- 2.0.54
- Disclosed:
- Nov 30, 2023
CVE-2023-51666 on NVD →
Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins [related-post] < 2.0.54
unknown
The Related Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.0.53 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level...
- Affected:
- up to 2.0.54
- Fixed in:
- 2.0.54
- Disclosed:
- Nov 30, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database