<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:wpxpress:post_grid_gutenberg_blocks_–_postx:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3awpxpresspost_grid_gutenberg_blocks__postxwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:53:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3awpxpresspost_grid_gutenberg_blocks__postxwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Post Grid Gutenberg Blocks - PostX Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-postx-xss/</link><pubDate>Sat, 10 Oct 2026 07:53:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-postx-xss/</guid><description>The Post Grid Gutenberg Blocks - PostX WordPress plugin (&lt;= 5.1.0) is vulnerable to stored Cross-Site Scripting via the display_name field due to insufficient sanitization of double-quotes.</description><content:encoded><![CDATA[<p>The Post Grid Gutenberg Blocks - PostX plugin for WordPress, in all versions up to and including 5.1.0, contains a stored Cross-Site Scripting (XSS) vulnerability. The issue stems from insufficient input sanitization and output escaping within the display_name user field. While WordPress core applies partial encoding to characters like ampersands and brackets, it does not encode double-quotes (due to ENT_NOQUOTES usage). This oversight allows an attacker with Subscriber-level access to inject a payload containing double-quotes via the /wp-admin/profile.php endpoint. The malicious payload is subsequently rendered on the frontend in the Archive_Title.php file at line 144, where it breaks out of an HTML attribute, enabling the execution of arbitrary JavaScript when an unsuspecting user, such as an administrator, views the compromised page. This vulnerability poses a significant risk to site integrity and administrative session security.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated or low-privileged attackers to execute arbitrary JavaScript in the context of the victim's session. This can lead to the theft of administrative session cookies, unauthorized administrative actions, or defacement of the website. The vulnerability affects all sites utilizing the affected versions of the PostX plugin.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the Post Grid Gutenberg Blocks - PostX plugin to a version beyond 5.1.0 as soon as a security update is released by the vendor.</li>
<li>Audit current WordPress user display names for suspicious characters, specifically double-quotes, to identify potential exploitation attempts.</li>
<li>Implement a strict Content Security Policy (CSP) to mitigate the impact of XSS vulnerabilities by restricting the execution of unauthorized scripts.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>