Executive brief
The PostX plugin for WordPress, which provides advanced layout blocks for website design, contains a security flaw that allows users with contributor-level access to inject malicious scripts into pages. This is particularly dangerous because a low-privileged user could create a draft post that, when previewed by a site administrator, executes code in the administrator's browser. This could lead to unauthorized site modifications or the theft of sensitive administrative session information.
Technical details
The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'searchnoresult' block attribute. An authenticated attacker with at least Contributor-level permissions can inject malicious JavaScript into a block. When an Editor or Administrator previews or views the post containing this block, the script executes within their browser context. This cross-privilege escalation vector can be used to perform actions on behalf of the administrator. The vulnerability is present in all versions up to and including 5.0.32.
Affected products
- WPXPO Post Grid Gutenberg Blocks – PostX up to, and including, 5.0.32
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory
References
- https://plugins.trac.wordpress.org/browser/ultimate-post/tags/5.0.32/blocks/Advanced_Search.php
- https://plugins.trac.wordpress.org/browser/ultimate-post/tags/5.0.32/blocks/Advanced_Search.php
- https://plugins.trac.wordpress.org/browser/ultimate-post/tags/5.0.32/classes/Blocks.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3613430%40ultimate-post&new=3613430%40ultimate-post
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1f645d0c-d641-4fff-a4f4-33c037de30e9?source=cve