WordPress PostX β Gutenberg Blocks for Post Grid Plugin <= 2.9.9 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-36385
7.1HIGH
What is CVE-2023-36385?
A reflected Cross-Site Scripting (XSS) vulnerability in the PostX β Gutenberg Post Grid Blocks plugin enables attackers to inject malicious scripts into the web page. This occurs when user input is not properly sanitized, allowing the execution of unintended scripts in a victim's browser, which can lead to session hijacking, data theft, or defacement of the website.
Affected Version(s)
PostX 0 <= 2.9.9