Extension WordPress

Vulnérabilités Post Grid Gutenberg Blocks – PostX

Cette page rassemble les failles publiées pour Post Grid Gutenberg Blocks – PostX, leurs plages de versions affectées et les correctifs signalés dans la base locale.

25Vulnérabilités
0Critiques
25Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Post Grid Gutenberg Blocks – PostX

25 fiches

CVE-2026-13253 Moyenne · 6,4
Post Grid Gutenberg Blocks – PostX

Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block Attribute

The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attribute of the ultimate-post/advanced-search block in versions up to and including 5.0.31. This is due to insufficient input sanitization and output escaping…

Versions affectées

*-5.0.31

Correctif

5.0.32

Publication

08/07/2026

CVE-2026-0718 Moyenne · 5,3
Post Grid Gutenberg Blocks – PostX

Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.5 – Missing Authorization to Limited Post Meta Modification

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ultp_shareCount_callback() function in all versions up to, and…

Versions affectées

*-5.0.5

Correctif

5.0.6

Publication

15/04/2026

CVE-2026-1273 Élevée · 7,2
Post Grid Gutenberg Blocks – PostX

PostX <= 5.0.8 – Authenticated (Administrator+) Server-Side Request Forgery via REST API Endpoints

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.8 via the `/ultp/v3/starter_dummy_post/` and `/ultp/v3/starter_import_content/` REST API endpoints. This…

Versions affectées

*-5.0.8

Correctif

5.0.9

Publication

03/03/2026

CVE-2025-12980 Élevée · 7,5
Post Grid Gutenberg Blocks – PostX

Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.3 – Missing Authorization to Unauthenticated Sensitive Information Exposure

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '/ultp/v2/get_dynamic_content/' REST API endpoint in all versions up…

Versions affectées

*-5.0.3

Correctif

5.0.4

Publication

20/12/2025

CVE-2025-31096 Moyenne · 6,4
Post Grid Gutenberg Blocks – PostX

PostX <= 4.1.25 – Authenticated (Contributor+) Stored Cross-Site Scripting

The PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-4.1.25

Correctif

4.1.26

Publication

28/03/2025

CVE-2024-53818 Moyenne · 6,4
Post Grid Gutenberg Blocks – PostX

PostX <= 4.1.15 – Authenticated (Contributor+) Stored Cross-Site Scripting

The PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-4.1.15

Correctif

4.1.16

Publication

02/12/2024

CVE-2024-10728 Élevée · 8,8
Post Grid Gutenberg Blocks – PostX

PostX <= 4.1.16 – Missing Authorization to Arbitrary Plugin Installation/Activation

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up to, and including, 4.1.16.…

Versions affectées

*-4.1.16

Correctif

4.1.17

Publication

15/11/2024

CVE-2024-50513 Moyenne · 6,4
Post Grid Gutenberg Blocks – PostX

PostX <= 4.1.15 – Authenticated (Author+) Stored Cross-Site Scripting

The PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above,…

Versions affectées

*-4.1.15

Correctif

4.1.16

Publication

28/10/2024

CVE-2024-50443 Moyenne · 6,4
Post Grid Gutenberg Blocks – PostX

PostX <= 4.1.12 – Authenticated (Contributor+) Stored Cross-Site Scripting

The PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-4.1.12

Correctif

4.1.13

Publication

24/10/2024

CVE-2024-5223 Moyenne · 6,4
Post Grid Gutenberg Blocks – PostX

Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.1 – Authenticated (Author+) Stored Cross-Site Scripting

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploading feature in all versions up to, and including, 4.1.1 due to insufficient input…

Versions affectées

*-4.1.1

Correctif

4.1.2

Publication

29/05/2024

CVE-2024-5326 Élevée · 8,8
Post Grid Gutenberg Blocks – PostX

Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 – Missing Authorization to Arbitrary Options Update

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'postx_presets_callback' function in all versions up to, and including,…

Versions affectées

*-4.1.2

Correctif

4.1.3

Publication

29/05/2024

CVE-2024-4305 Moyenne · 6,4
Post Grid Gutenberg Blocks – PostX

Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.0.4 – Authenticated (Contributor+) Stored Cross=Site Scripting

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the filterMobileText parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and…

Versions affectées

*-4.0.4

Correctif

4.1.0

Publication

27/05/2024

CVE-2024-3239 Moyenne · 6,4
Post Grid Gutenberg Blocks – PostX

Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-4.0.1

Correctif

4.0.2

Publication

22/04/2024

CVE-2024-32564 Moyenne · 6,4
Post Grid Gutenberg Blocks – PostX

Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-4.0.1

Correctif

4.0.2

Publication

16/04/2024

CVE-2023-3992 Moyenne · 6,1
Post Grid Gutenberg Blocks – PostX

PostX – Gutenberg Post Grid Blocks <= 3.0.5 – Reflected Cross-Site Scripting via 'postx_type'

The PostX – Gutenberg Post Grid Blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘postx_type’ parameter in versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-3.0.5

Correctif

3.0.6

Publication

02/08/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités