Sceawere
Vulnerability Detail
CVE-2026-96840UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
PostX Stored Cross-Site Scripting
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- wpxpo
- Product
- Post Grid Gutenberg Blocks – PostX
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via display_name User Field in all versions up to, and including, 5.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress core's pre_user_display_name filter encodes &, <, and > but leaves double-quotes intact (ENT_NOQUOTES), allowing a Subscriber-level user to store a double-quote in their display_name via /wp-admin/profile.php that subsequently breaks out of the alt="" attribute at Archive_Title.php:144.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T07:16:42.767Z",
"pubdate": "2026-10-10T07:16:42.767Z",
"executiveSummary": "The Post Grid Gutenberg Blocks – PostX plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability in versions up to and including 5.1.0.\nThe vulnerability arises from insufficient input sanitization and output escaping when handling the display_name user field.\nThis flaw enables authenticated attackers with Subscriber-level privileges to inject arbitrary JavaScript into WordPress pages.\nWhen a victim views an injected page, the malicious script executes within the context of their session, potentially leading to unauthorized actions, account takeover, or session hijacking.\nThe issue stems from a failure to properly handle double-quote characters when rendering user display names in the plugin's frontend components.\nThe vulnerability is accessible to any user with the ability to modify their profile information, presenting a significant security risk for multi-user WordPress environments.",
"technicalDetails": "The vulnerability resides in the way PostX handles user display names within its grid blocks, specifically identified at Archive_Title.php:144.\nWhile WordPress core applies the pre_user_display_name filter, it utilizes the ENT_NOQUOTES flag, which encodes ampersands and angle brackets but permits the persistence of double-quote characters. This behavior allows a user to store a malicious payload containing double-quotes within their profile metadata via /wp-admin/profile.php.\nThe exploitation mechanism leverages the lack of secondary output escaping in the PostX plugin. When the Archive_Title.php component retrieves the display_name for rendering, it injects the unsanitized value directly into an HTML attribute, specifically the alt='' attribute of an image or element.\nBecause the plugin does not escape double-quotes before this insertion, an attacker can break out of the intended HTML attribute context. For example, by inputting a payload structured as '\" onmouseover=\"alert(document.cookie)\", the attacker successfully terminates the alt attribute and injects a new event handler into the tag.\nThe attack flow proceeds as follows: 1) An attacker authenticates as a Subscriber and navigates to their profile settings. 2) The attacker updates their 'Display name publicly as' field to include an XSS vector containing a double-quote. 3) The malicious string is saved to the WordPress database. 4) The attacker creates or visits a page utilizing a vulnerable PostX block that displays the author name. 5) When a target user (such as an Administrator) views the page, the browser parses the broken HTML attribute and executes the injected JavaScript.\nThe impact of successful exploitation includes the execution of arbitrary scripts in the victim's browser, enabling session hijacking, redirection to malicious domains, or the unauthorized execution of administrative actions within the WordPress dashboard if the victim possesses sufficient privileges."
}