Impact
The Post Grid Gutenberg Blocks – PostX plugin contains a vulnerability that permits authenticated WordPress users with Contributor or higher privileges to embed arbitrary web scripts into the "searchnoresult" block attribute. When a malicious block attribute is saved, the injected JavaScript is stored in the database and executed whenever a post containing the block is viewed by privileged users. This flaw can lead to client‑side code execution, potentially enabling credential theft, session hijack, phishing, or other browser‑based attacks against editors and administrators.
Affected Systems
All versions of the Post Grid Gutenberg Blocks – PostX plugin up to and including 5.0.32 are affected. The vulnerability exists in the plugin’s block implementation within WordPress, and any blog running these versions with enabled contributor‑level editing capabilities is at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4, indicating medium severity, while the EPSS score of < 1% suggests a very low current exploitation probability in the wild. The flaw is not listed in the CISA KEV catalog. Attackers must first attain Contributor or higher access, inject the malicious attribute, and then wait for an administrator or editor to preview or view the affected post, which provides the execution context.
OpenCVE Enrichment