Impact
The PostX plugin for WordPress is affected by insufficient input sanitization and output escaping of the inputPlaceHolder parameter, which allows authenticated attackers with Contributor level or higher to store malicious scripts in post comments. These scripts are executed whenever a user visits the injected page, enabling arbitrary JavaScript execution in the context of the site, potentially leading to phishing, session theft, or defacement.
Affected Systems
All installations of the Post Grid Gutenberg Blocks – PostX plugin for WordPress up to and including version 5.0.13 are affected. Sites that rely on the plugin’s comment functionality, such as news, magazine, or blog WordPress sites, may be vulnerable if they have logged-in users with Contributor or higher privileges.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4, indicating moderate severity, and is not listed in CISA KEV. The EPSS score is not available. Exploitation requires authenticated access with Contributor or higher privileges; attackers who gain such access can persistently inject scripts that affect all site visitors, representing a moderate but significant risk of widespread compromise within an impacted environment.
OpenCVE Enrichment