Team Showcase <= 1.22.28 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.22.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 1.22.28
- Fix:
- No patched version reported
- Disclosed:
- May 25, 2026
CVE-2025-62745 on NVD →
Team Showcase [team] < 1.22.26
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Reflected XSS.This issue affects Team Showcase: from n/a through 1.22.25.
- Affected:
- up to 1.22.26
- Fixed in:
- 1.22.26
- Disclosed:
- Sep 17, 2024
CVE-2024-44002 on NVD →
Team Showcase <= 1.22.25 - Reflected Cross-Site Scripting
medium
The Team Showcase plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.22.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...
- CVSS:
- 6.1
- Affected:
- up to 1.22.25
- Fixed in:
- 1.22.26
- Disclosed:
- Sep 16, 2024
CVE-2024-44002 on NVD →
Team Showcase [team] < 1.22.24
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS.This issue affects Team Showcase: from n/a through 1.22.23.
- Affected:
- up to 1.22.24
- Fixed in:
- 1.22.24
- Disclosed:
- Aug 18, 2024
CVE-2024-43321 on NVD →
Team Showcase <= 1.22.23 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.22.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 1.22.23
- Fixed in:
- 1.22.24
- Disclosed:
- Aug 16, 2024
CVE-2024-43321 on NVD →
Team Showcase [team] < 1.22.16
unknown
[en] PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_i...
- Affected:
- up to 1.22.16
- Fixed in:
- 1.22.16
- Disclosed:
- Jan 1, 2021
CVE-2020-35939 on NVD →
Team Showcase [team] < 1.22.16
unknown
[en] Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.
- Affected:
- up to 1.22.16
- Fixed in:
- 1.22.16
- Disclosed:
- Jan 1, 2021
CVE-2020-35937 on NVD →
Team Showcase [team] < 1.22.16
unknown
[en] Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.
- Affected:
- up to 1.22.16
- Fixed in:
- 1.22.16
- Disclosed:
- Jan 1, 2021
CVE-2020-35936 on NVD →
Team Showcase [team] < 1.22.16
unknown
PHP Object Injection vulnerability found by Ramuel Gall (Wordfence) in WordPress Team Showcase plugin (versions <= 1.22.15).
- Affected:
- up to 1.22.16
- Fixed in:
- 1.22.16
- Disclosed:
- Oct 5, 2020
Team Showcase [team] < 1.22.16
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Ramuel Gall (Wordfence) in WordPress Team Showcase plugin (versions <= 1.22.15).
- Affected:
- up to 1.22.16
- Fixed in:
- 1.22.16
- Disclosed:
- Oct 5, 2020
Team Showcase <= 1.22.15 - Object Injection
high
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import...
- CVSS:
- 7.5
- Affected:
- up to 1.22.16
- Fixed in:
- 1.22.16
- Disclosed:
- Sep 17, 2020
CVE-2020-35938 on NVD →
Team Showcase <= 1.22.15 - Stored Cross-Site Scripting
high
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.
- CVSS:
- 7.5
- Affected:
- up to 1.22.16
- Fixed in:
- 1.22.16
- Disclosed:
- Sep 17, 2020
CVE-2020-35937 on NVD →
Team Showcase <= 1.22.15 - Stored Cross-Site Scripting
high
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.
- CVSS:
- 7.5
- Affected:
- up to 1.22.16
- Fixed in:
- 1.22.16
- Disclosed:
- Sep 17, 2020
CVE-2020-35936 on NVD →
Team Showcase <= 1.22.15 - Object Injection
high
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import...
- CVSS:
- 7.5
- Affected:
- up to 1.22.16
- Fixed in:
- 1.22.16
- Disclosed:
- Sep 17, 2020
CVE-2020-35939 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database