Filtered by vendor Wpxpo
                         Subscriptions
                    
                    
                
                        Filtered by product Postx
                         Subscriptions
                    
                    
                
                    Total
                    8 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2024-50443 | 1 Wpxpo | 1 Postx | 2025-09-29 | 6.5 Medium | 
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Post Grid Team by WPXPO PostX allows Stored XSS.This issue affects PostX: from n/a through 4.1.12. | ||||
| CVE-2025-31096 | 2 Wordpress, Wpxpo | 2 Wordpress, Postx | 2025-07-13 | 6.5 Medium | 
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX allows DOM-Based XSS. This issue affects PostX: from n/a through 4.1.25. | ||||
| CVE-2024-10728 | 1 Wpxpo | 2 Postx, Postx - Gutenberg Blocks For Post Grid | 2025-07-09 | 8.8 High | 
| The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up to, and including, 4.1.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. | ||||
| CVE-2024-3239 | 1 Wpxpo | 1 Postx | 2025-05-14 | 5.4 Medium | 
| The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | ||||
| CVE-2024-4305 | 2 Wpdownloadmanager, Wpxpo | 2 Gutenberg Blocks For Wordpress Download Manager, Postx | 2025-05-13 | 6.8 Medium | 
| The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | ||||
| CVE-2023-3992 | 1 Wpxpo | 1 Postx | 2025-04-23 | 6.1 Medium | 
| The PostX WordPress plugin before 3.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | ||||
| CVE-2024-31246 | 1 Wpxpo | 1 Postx | 2024-11-21 | 5.4 Medium | 
| Missing Authorization vulnerability in Post Grid Team by WPXPO PostX – Gutenberg Blocks for Post Grid.This issue affects PostX – Gutenberg Blocks for Post Grid: from n/a through 3.2.3. | ||||
| CVE-2023-36385 | 1 Wpxpo | 1 Postx | 2024-11-21 | 7.1 High | 
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpxpo PostX – Gutenberg Post Grid Blocks plugin <= 2.9.9 versions. | ||||
                            
                                
                                
                                    Page 1 of 1.