Stored XSS in Post Grid Gutenberg Blocks - PostX Plugin
The Post Grid Gutenberg Blocks - PostX WordPress plugin (<= 5.1.0) is vulnerable to stored Cross-Site Scripting via the display_name field due to insufficient sanitization of double-quotes.
CVE search metadata
CVE search record: CVE-2026-96840. Severity: high. CVSS: 7.2. KEV: no. Product: Post Grid Gutenberg Blocks – PostX (<= 5.1.0). Brief: Stored XSS in Post Grid Gutenberg Blocks - PostX Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-postx-xss/
The Post Grid Gutenberg Blocks - PostX plugin for WordPress, in all versions up to and including 5.1.0, contains a stored Cross-Site Scripting (XSS) vulnerability. The issue stems from insufficient input sanitization and output escaping within the display_name user field. While WordPress core applies partial encoding to characters like ampersands and brackets, it does not encode double-quotes (due to ENT_NOQUOTES usage). This oversight allows an attacker with Subscriber-level access to inject a payload containing double-quotes via the /wp-admin/profile.php endpoint. The malicious payload is subsequently rendered on the frontend in the Archive_Title.php file at line 144, where it breaks out of an HTML attribute, enabling the execution of arbitrary JavaScript when an unsuspecting user, such as an administrator, views the compromised page. This vulnerability poses a significant risk to site integrity and administrative session security.
Impact
Successful exploitation allows unauthenticated or low-privileged attackers to execute arbitrary JavaScript in the context of the victim's session. This can lead to the theft of administrative session cookies, unauthorized administrative actions, or defacement of the website. The vulnerability affects all sites utilizing the affected versions of the PostX plugin.
Recommendation
- Upgrade the Post Grid Gutenberg Blocks - PostX plugin to a version beyond 5.1.0 as soon as a security update is released by the vendor.
- Audit current WordPress user display names for suspicious characters, specifically double-quotes, to identify potential exploitation attempts.
- Implement a strict Content Security Policy (CSP) to mitigate the impact of XSS vulnerabilities by restricting the execution of unauthorized scripts.
Immediate actions
Review WordPress user profiles for malicious scripts in display_name fields
Mitigations
Upgrade PostX plugin once a fix is released or disable the plugin if not critical
CVE-2026-96840