{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awpxpresspost_grid_gutenberg_blocks__postxwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpxpress:post_grid_gutenberg_blocks_–_postx:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96840"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Post Grid Gutenberg Blocks – PostX (\u003c= 5.1.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Post Grid Gutenberg Blocks - PostX plugin for WordPress, in all versions up to and including 5.1.0, contains a stored Cross-Site Scripting (XSS) vulnerability. The issue stems from insufficient input sanitization and output escaping within the display_name user field. While WordPress core applies partial encoding to characters like ampersands and brackets, it does not encode double-quotes (due to ENT_NOQUOTES usage). This oversight allows an attacker with Subscriber-level access to inject a payload containing double-quotes via the /wp-admin/profile.php endpoint. The malicious payload is subsequently rendered on the frontend in the Archive_Title.php file at line 144, where it breaks out of an HTML attribute, enabling the execution of arbitrary JavaScript when an unsuspecting user, such as an administrator, views the compromised page. This vulnerability poses a significant risk to site integrity and administrative session security.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated or low-privileged attackers to execute arbitrary JavaScript in the context of the victim's session. This can lead to the theft of administrative session cookies, unauthorized administrative actions, or defacement of the website. The vulnerability affects all sites utilizing the affected versions of the PostX plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Post Grid Gutenberg Blocks - PostX plugin to a version beyond 5.1.0 as soon as a security update is released by the vendor.\u003c/li\u003e\n\u003cli\u003eAudit current WordPress user display names for suspicious characters, specifically double-quotes, to identify potential exploitation attempts.\u003c/li\u003e\n\u003cli\u003eImplement a strict Content Security Policy (CSP) to mitigate the impact of XSS vulnerabilities by restricting the execution of unauthorized scripts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-10T07:53:08Z","date_published":"2026-10-10T07:53:08Z","id":"https://feed.craftedsignal.io/briefs/2026-10-postx-xss/","summary":"The Post Grid Gutenberg Blocks - PostX WordPress plugin (\u003c= 5.1.0) is vulnerable to stored Cross-Site Scripting via the display_name field due to insufficient sanitization of double-quotes.","title":"Stored XSS in Post Grid Gutenberg Blocks - PostX Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-postx-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wpxpress:post_grid_gutenberg_blocks_–_postx:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}