{
 "id": "WPSEC-2026-0441",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0441/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0441/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0441/index.md",
 "title": "Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.41 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Archive Title Block",
 "description": "The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Archive Title block in versions 2.7.0 to 5.0.41. The archive title is printed without escaping in the image alt attribute, and on author archive pages that title is the author's display name, which each user can set. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts through their display name that execute whenever a user visits their author archive page. Exploitation requires a PostX archive template that applies to author archives and contains the Archive Title block with its image enabled.",
 "plugin": {
  "slug": "ultimate-post",
  "name": "Post Grid Gutenberg Blocks for News, Magazines, Blog Websites",
  "full_name": "Post Grid Gutenberg Blocks – PostX",
  "wordpress_org": "https://wordpress.org/plugins/ultimate-post/",
  "advisories_url": "https://wpsec.com/vuln/plugin/ultimate-post/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/ultimate-post"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.9,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.7.0",
    "from_inclusive": true,
    "to": "5.1.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.7.0 before 5.1.0"
  ]
 },
 "introduced_in": "2.7.0",
 "fixed_in": "5.1.0",
 "remediation": "Update to 5.1.0 or later.",
 "fix_released": "2026-10-04T09:06:16+00:00",
 "published": "2026-10-06T14:47:47+00:00",
 "updated": "2026-10-06T14:18:53.003013+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0441/",
  "https://plugins.svn.wordpress.org/ultimate-post/tags/5.1.0/",
  "https://wordpress.org/plugins/ultimate-post/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/ultimate-post",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-06"
 }
}