Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.41 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Archive Title Block
- ID
- WPSEC-2026-0441
- Plugin
- Post Grid Gutenberg Blocks – PostX (ultimate-post)
- Affected
- from 2.7.0 before 5.1.0
- Remediation
- Update to 5.1.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
- Attack surface
- Post Grid Gutenberg Blocks for News, Magazines, Blog Websites on WPSec AttackSurface
- Fix released
- Published
Description
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Archive Title block in versions 2.7.0 to 5.0.41. The archive title is printed without escaping in the image alt attribute, and on author archive pages that title is the author's display name, which each user can set. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts through their display name that execute whenever a user visits their author archive page. Exploitation requires a PostX archive template that applies to author archives and contains the Archive Title block with its image enabled.
References
- https://wpsec.com/vuln/WPSEC-2026-0441/
- https://plugins.svn.wordpress.org/ultimate-post/tags/5.1.0/
- https://wordpress.org/plugins/ultimate-post/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS