VYPR

Smart Post Show

by WordPress

CVEs (4)

  • CVE-2026-10735HigJun 24, 2026
    risk 0.49cvss 7.5epss 0.00

    Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin…

  • CVE-2026-3017HigApr 14, 2026
    risk 0.40cvss 7.2epss 0.01

    The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it…

  • CVE-2024-8187MedMay 15, 2025
    risk 0.31cvss 4.8epss 0.00

    The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2024-3996LowMay 15, 2025
    risk 0.23cvss 3.5epss 0.00

    The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…