Extension WordPress
Vulnérabilités Post Grid Gutenberg Blocks – PostX
Cette page rassemble les failles publiées pour Post Grid Gutenberg Blocks – PostX, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Post Grid Gutenberg Blocks – PostX
25 fiches
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block Attribute
The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attribute of the ultimate-post/advanced-search block in versions up to and including 5.0.31. This is due to insufficient input sanitization and output escaping…
*-5.0.31
5.0.32
08/07/2026
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.5 – Missing Authorization to Limited Post Meta Modification
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ultp_shareCount_callback() function in all versions up to, and…
*-5.0.5
5.0.6
15/04/2026
PostX <= 5.0.8 – Authenticated (Administrator+) Server-Side Request Forgery via REST API Endpoints
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.8 via the `/ultp/v3/starter_dummy_post/` and `/ultp/v3/starter_import_content/` REST API endpoints. This…
*-5.0.8
5.0.9
03/03/2026
PostX <= 5.0.3 – Missing Authorization
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.3. This…
*-5.0.3
5.0.4
19/01/2026
PostX <= 5.0.3 – Unauthenticated Information Exposure
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.0.3. This makes it possible for unauthenticated attackers to extract…
*-5.0.3
5.0.4
21/12/2025
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.3 – Missing Authorization to Unauthenticated Sensitive Information Exposure
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '/ultp/v2/get_dynamic_content/' REST API endpoint in all versions up…
*-5.0.3
5.0.4
20/12/2025
PostX <= 4.1.36 – Missing Authorization
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.1.36. This…
*-4.1.36
4.1.37
02/09/2025
PostX <= 4.1.35 – Authenticated (Editor+) Privilege Escalation
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.35. This makes it possible for authenticated attackers, with Editor-level access…
*-4.1.35
4.1.36
29/08/2025
PostX <= 4.1.25 – Authenticated (Contributor+) Stored Cross-Site Scripting
The PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-4.1.25
4.1.26
28/03/2025
PostX <= 4.1.15 – Authenticated (Contributor+) Stored Cross-Site Scripting
The PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-4.1.15
4.1.16
02/12/2024
PostX <= 4.1.16 – Missing Authorization to Arbitrary Plugin Installation/Activation
The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up to, and including, 4.1.16.…
*-4.1.16
4.1.17
15/11/2024
PostX <= 4.1.15 – Authenticated (Author+) Stored Cross-Site Scripting
The PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above,…
*-4.1.15
4.1.16
28/10/2024
PostX <= 4.1.12 – Authenticated (Contributor+) Stored Cross-Site Scripting
The PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-4.1.12
4.1.13
24/10/2024
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.1 – Authenticated (Author+) Stored Cross-Site Scripting
The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploading feature in all versions up to, and including, 4.1.1 due to insufficient input…
*-4.1.1
4.1.2
29/05/2024
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 – Missing Authorization to Arbitrary Options Update
The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'postx_presets_callback' function in all versions up to, and including,…
*-4.1.2
4.1.3
29/05/2024
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.0.4 – Authenticated (Contributor+) Stored Cross=Site Scripting
The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the filterMobileText parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and…
*-4.0.4
4.1.0
27/05/2024
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping on user…
*-4.0.1
4.0.2
22/04/2024
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping on user…
*-4.0.1
4.0.2
16/04/2024
PostX – Gutenberg Blocks for Post Grid <= 3.2.3 – Incorrect Authorization
The PostX – Gutenberg Blocks for Post Grid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in versions up to, and including, 3.2.3. This makes it possible…
*-3.2.3
3.2.4
05/04/2024
PostX – Gutenberg Post Grid Blocks <= 3.0.5 – Reflected Cross-Site Scripting via 'postx_type'
The PostX – Gutenberg Post Grid Blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘postx_type’ parameter in versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it…
*-3.0.5
3.0.6
02/08/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.