Stored Cross-Site Scripting in Post Grid Gutenberg Blocks Plugin for WordPress
CVE-2026-15100
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 July 2026
What is CVE-2026-15100?
The Post Grid Gutenberg Blocks β PostX plugin for WordPress contains a vulnerability that allows for Stored Cross-Site Scripting. This issue arises due to inadequate input sanitization and output escaping in the 'searchnoresult' block attribute. Authenticated users with contributor-level access or higher can exploit this flaw to inject malicious JavaScript into posts. When a user accesses a page containing this injected script, it executes in their browser, posing significant risks, especially in scenarios where a Contributor's draft post is previewed by Editors or Administrators.
Affected Version(s)
Post Grid Gutenberg Blocks β PostX 0 <= 5.0.32