Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.41 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Archive Title Block

Medium 4.9 CWE-79Fixed in 5.1.0
ID
WPSEC-2026-0441
Plugin
Post Grid Gutenberg Blocks – PostX (ultimate-post)
Affected
from 2.7.0 before 5.1.0
Remediation
Update to 5.1.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites on WPSec AttackSurface
Fix released
Published

Description

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Archive Title block in versions 2.7.0 to 5.0.41. The archive title is printed without escaping in the image alt attribute, and on author archive pages that title is the author's display name, which each user can set. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts through their display name that execute whenever a user visits their author archive page. Exploitation requires a PostX archive template that applies to author archives and contains the Archive Title block with its image enabled.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0