VYPR

PostX – Gutenberg Blocks for Post Grid

by WordPress

CVEs (4)

  • CVE-2023-36385HigJul 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpxpo PostX – Gutenberg Post Grid Blocks plugin <= 2.9.9 versions.

  • CVE-2021-24660MedSep 27, 2021
    risk 0.35cvss 5.4epss 0.01

    The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.

  • CVE-2021-24659MedSep 27, 2021
    risk 0.35cvss 5.4epss 0.01

    The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.

  • CVE-2026-15100MedJul 24, 2026
    risk 0.00cvss 6.4epss 0.00

    The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all versions up to, and including, 5.0.32 due to insufficient input sanitization and output escaping. This makes it possible for…