Junglewise Threat Intelligence

CVE-2026-15100: WPXPO PostX Stored XSS in searchnoresult block attribute

CVE-2026-15100 · Severity: medium · CVSS 6.4 · Published 2026-07-24

Vendors: WPXPO.

Executive brief

The PostX plugin for WordPress, which provides advanced layout blocks for website design, contains a security flaw that allows users with contributor-level access to inject malicious scripts into pages. This is particularly dangerous because a low-privileged user could create a draft post that, when previewed by a site administrator, executes code in the administrator's browser. This could lead to unauthorized site modifications or the theft of sensitive administrative session information.

Technical details

The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'searchnoresult' block attribute. An authenticated attacker with at least Contributor-level permissions can inject malicious JavaScript into a block. When an Editor or Administrator previews or views the post containing this block, the script executes within their browser context. This cross-privilege escalation vector can be used to perform actions on behalf of the administrator. The vulnerability is present in all versions up to and including 5.0.32.

Affected products

  • WPXPO Post Grid Gutenberg Blocks – PostX up to, and including, 5.0.32

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References

Related threats