Impact
The vulnerability allows an authenticated user with contributor‑level or higher permissions to inject malicious scripts into the "moreResultsText" attribute of the advanced‑search block in the Post Grid Gutenberg Blocks – PostX plugin. It is only filtered with wp_kses() and not escaped with esc_attr(), so an attacker can embed JavaScript that will be executed whenever any user opens a page containing the infected block, leading to arbitrary web script execution.
Affected Systems
The affected product is the Post Grid Gutenberg Blocks – PostX plugin for WordPress. Versions up to and including 5.0.31 are impacted. Site administrators should verify the current plugin version and take action if it falls within the affected range.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score is less than 1%, indicating a low exploitation probability across the ecosystem. The vulnerability is not listed in the CISA KEV catalog. It requires an authenticated user with contributor or higher role and the ability to edit or create the advanced‑search block. Once injected, the script will execute in the browsers of all users who view the page.
OpenCVE Enrichment