CVE-2026-5158
- EPSS 0.16%
- Veröffentlicht 06.08.2026 11:29:19
- Zuletzt bearbeitet 12.08.2026 21:00:37
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inputPlaceHolder' parameter in all versions up to, and including, 5.0.13 due to insufficient input sa...
CVE-2026-15100
- EPSS 0.19%
- Veröffentlicht 24.07.2026 02:31:58
- Zuletzt bearbeitet 24.07.2026 20:45:45
The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all versions up to, and including, 5.0.32 due to insufficient input sanitization and output escaping. Thi...
CVE-2026-13253
- EPSS 0.2%
- Veröffentlicht 09.07.2026 06:52:44
- Zuletzt bearbeitet 09.07.2026 18:16:50
The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attribute of the ultimate-post/advanced-search block in versions up to and including 5.0.31. This is due to insufficient input sanitiz...
CVE-2026-0718
- EPSS 0.28%
- Veröffentlicht 16.04.2026 07:39:50
- Zuletzt bearbeitet 22.04.2026 20:22:50
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ultp_shareCount_callback() function in all versions up to, and ...
CVE-2026-1273
- EPSS 0.31%
- Veröffentlicht 04.03.2026 01:21:59
- Zuletzt bearbeitet 22.04.2026 21:26:58
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.8 via the `/ultp/v3/starter_dummy_post/` and `/ultp/v3/starter_impor...
CVE-2025-69313
- EPSS 0.29%
- Veröffentlicht 22.01.2026 16:52:32
- Zuletzt bearbeitet 15.04.2026 00:35:42
Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PostX: from n/a through <= 5.0.3.
CVE-2025-68606
- EPSS 0.21%
- Veröffentlicht 24.12.2025 13:10:48
- Zuletzt bearbeitet 27.04.2026 19:16:36
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPXPO PostX ultimate-post allows Retrieve Embedded Sensitive Data.This issue affects PostX: from n/a through <= 5.0.3.
CVE-2025-12980
- EPSS 0.32%
- Veröffentlicht 21.12.2025 02:20:32
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '/ultp/v2/get_dynamic_content/' REST API endpoint in all versions up ...
CVE-2025-55707
- EPSS 0.39%
- Veröffentlicht 18.12.2025 07:21:50
- Zuletzt bearbeitet 15.04.2026 00:35:42
Incorrect Privilege Assignment vulnerability in WPXPO PostX ultimate-post allows Privilege Escalation.This issue affects PostX: from n/a through <= 4.1.35.
CVE-2025-54751
- EPSS 0.25%
- Veröffentlicht 18.12.2025 07:21:50
- Zuletzt bearbeitet 15.04.2026 00:35:42
Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PostX: from n/a through <= 4.1.36.