# Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.41 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Archive Title Block

- **ID:** WPSEC-2026-0441
- **Plugin:** Post Grid Gutenberg Blocks – PostX (`ultimate-post`), https://wordpress.org/plugins/ultimate-post/
- **Affected versions:** from 2.7.0 before 5.1.0
- **Fixed in:** 5.1.0 (Update to 5.1.0 or later.)
- **Severity:** Medium 4.9 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/ultimate-post
- **Fix released:** 2026-10-04
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0441/

## Description

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Archive Title block in versions 2.7.0 to 5.0.41. The archive title is printed without escaping in the image alt attribute, and on author archive pages that title is the author's display name, which each user can set. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts through their display name that execute whenever a user visits their author archive page. Exploitation requires a PostX archive template that applies to author archives and contains the Archive Title block with its image enabled.

## References

- https://wpsec.com/vuln/WPSEC-2026-0441/
- https://plugins.svn.wordpress.org/ultimate-post/tags/5.1.0/
- https://wordpress.org/plugins/ultimate-post/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0441/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
