Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Post Grid Gutenberg Blocks – PostX Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 26 vulnerability records associated with Post Grid Gutenberg Blocks – PostX, published between 2021 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

26Total records
0Critical
6High
20Medium
0Low
0Informational
26Patched records
0Currently marked unpatched
2021-08-17First disclosure
2026-07-23Latest disclosure
26 of 26CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202144 records
202322 records
20241010 records
202555 records
202655 records

Severity Breakdown

SeverityRecordsShare
High623.1%
Medium2076.9%

Vulnerability-Type Breakdown

Cross-Site Scripting

14 records53.8%

First: 2021. Latest: 2026.

Missing Authorization

8 records30.8%

First: 2021. Latest: 2026.

Information Disclosure

2 records7.7%

First: 2021. Latest: 2025.

Privilege Escalation

1 record3.8%

First: 2025. Latest: 2025.

Other

1 record3.8%

First: 2026. Latest: 2026.

Patch Status

Patched
26
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 5.0.33
  • 5.0.32
  • 5.0.6
  • 5.0.9
  • 5.0.4
  • 4.1.37
  • 4.1.36
  • 4.1.26
  • 4.1.17
  • 4.1.16
  • 4.1.13
  • 4.1.2
  • 4.1.3
  • 4.1.0
  • 4.0.2
  • 3.2.4
  • 3.0.6
  • 2.9.10
  • 2.4.10

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-5.0.32Post Grid Gutenberg Blocks <= 5.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'searchnoresult' Block AttributeJuly 23, 20265.0.33Medium
*-5.0.31Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block AttributeJuly 8, 20265.0.32Medium
*-5.0.5Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.5 - Missing Authorization to Limited Post Meta ModificationApril 15, 20265.0.6Medium
*-5.0.8PostX <= 5.0.8 - Authenticated (Administrator+) Server-Side Request Forgery via REST API EndpointsMarch 3, 20265.0.9High
*-5.0.3PostX <= 5.0.3 - Missing AuthorizationJanuary 19, 20265.0.4Medium
*-5.0.3PostX <= 5.0.3 - Unauthenticated Information ExposureDecember 21, 20255.0.4Medium
*-5.0.3Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.3 - Missing Authorization to Unauthenticated Sensitive Information ExposureDecember 20, 20255.0.4High
*-4.1.36PostX <= 4.1.36 - Missing AuthorizationSeptember 2, 20254.1.37Medium
*-4.1.35PostX <= 4.1.35 - Authenticated (Editor+) Privilege EscalationAugust 29, 20254.1.36High
*-4.1.25PostX <= 4.1.25 - Authenticated (Contributor+) Stored Cross-Site ScriptingMarch 28, 20254.1.26Medium
*-4.1.15PostX <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site ScriptingDecember 2, 20244.1.16Medium
*-4.1.16PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/ActivationNovember 15, 20244.1.17High
*-4.1.15PostX <= 4.1.15 - Authenticated (Author+) Stored Cross-Site ScriptingOctober 28, 20244.1.16Medium
*-4.1.12PostX <= 4.1.12 - Authenticated (Contributor+) Stored Cross-Site ScriptingOctober 24, 20244.1.13Medium
*-4.1.1Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.1 - Authenticated (Author+) Stored Cross-Site ScriptingMay 29, 20244.1.2Medium
*-4.1.2Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 - Missing Authorization to Arbitrary Options UpdateMay 29, 20244.1.3High
*-4.0.4Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.0.4 - Authenticated (Contributor+) Stored Cross=Site ScriptingMay 27, 20244.1.0Medium
*-4.0.1Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.0.1 - Authenticated (Contributor+) Stored Cross-Site ScriptingApril 22, 20244.0.2Medium
*-4.0.1Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.0.1 - Authenticated (Contributor+) Stored Cross-Site ScriptingApril 16, 20244.0.2Medium
*-3.2.3PostX – Gutenberg Blocks for Post Grid <= 3.2.3 - Incorrect AuthorizationApril 5, 20243.2.4Medium
*-3.0.5PostX - Gutenberg Post Grid Blocks <= 3.0.5 - Reflected Cross-Site Scripting via 'postx_type'August 2, 20233.0.6Medium
*-2.9.9PostX – Gutenberg Blocks for Post Grid <= 2.9.9 - Unauthenticated Cross-Site ScriptingJune 23, 20232.9.10High
*-2.4.9PostX Gutenberg Blocks Saved Templates Addon <= 2.4.9 - Private Content DisclosureAugust 26, 20212.4.10Medium
[*, 2.4.10)PostX - Gutenberg Blocks for Post Grid <= 2.4.9 - Stored Cross-Site ScriptingAugust 26, 20212.4.10Medium
[*, 2.4.10)PostX - Gutenberg Blocks for Post Grid <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site ScriptingAugust 26, 20212.4.10Medium

Selected source records

Latest Records

MediumCVE-2026-15100

Post Grid Gutenberg Blocks <= 5.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'searchnoresult' Block Attribute

Published: July 23, 2026

Affected versions
*-5.0.32
Patched versions
5.0.33
Original Wordfence record
MediumCVE-2026-13253

Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block Attribute

Published: July 8, 2026

Affected versions
*-5.0.31
Patched versions
5.0.32
Original Wordfence record
MediumCVE-2026-0718

Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.5 - Missing Authorization to Limited Post Meta Modification

Published: April 15, 2026

Affected versions
*-5.0.5
Patched versions
5.0.6
Original Wordfence record
HighCVE-2026-1273

PostX <= 5.0.8 - Authenticated (Administrator+) Server-Side Request Forgery via REST API Endpoints

Published: March 3, 2026

Affected versions
*-5.0.8
Patched versions
5.0.9
Original Wordfence record
MediumCVE-2025-69313

PostX <= 5.0.3 - Missing Authorization

Published: January 19, 2026

Affected versions
*-5.0.3
Patched versions
5.0.4
Original Wordfence record
MediumCVE-2025-68606

PostX <= 5.0.3 - Unauthenticated Information Exposure

Published: December 21, 2025

Affected versions
*-5.0.3
Patched versions
5.0.4
Original Wordfence record
HighCVE-2025-12980

Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure

Published: December 20, 2025

Affected versions
*-5.0.3
Patched versions
5.0.4
Original Wordfence record
MediumCVE-2025-54751

PostX <= 4.1.36 - Missing Authorization

Published: September 2, 2025

Affected versions
*-4.1.36
Patched versions
4.1.37
Original Wordfence record

Highest-Severity Records

HighCVE-2024-10728

PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/Activation

Published: November 15, 2024

Affected versions
*-4.1.16
Patched versions
4.1.17
Original Wordfence record
HighCVE-2024-5326

Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update

Published: May 29, 2024

Affected versions
*-4.1.2
Patched versions
4.1.3
Original Wordfence record
HighCVE-2025-12980

Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure

Published: December 20, 2025

Affected versions
*-5.0.3
Patched versions
5.0.4
Original Wordfence record
HighCVE-2025-55707

PostX <= 4.1.35 - Authenticated (Editor+) Privilege Escalation

Published: August 29, 2025

Affected versions
*-4.1.35
Patched versions
4.1.36
Original Wordfence record
HighCVE-2026-1273

PostX <= 5.0.8 - Authenticated (Administrator+) Server-Side Request Forgery via REST API Endpoints

Published: March 3, 2026

Affected versions
*-5.0.8
Patched versions
5.0.9
Original Wordfence record
HighCVE-2023-36385

PostX – Gutenberg Blocks for Post Grid <= 2.9.9 - Unauthenticated Cross-Site Scripting

Published: June 23, 2023

Affected versions
*-2.9.9
Patched versions
2.9.10
Original Wordfence record
MediumCVE-2021-24652

PostX - Gutenberg Blocks for Post Grid <= 2.4.9 - Unauthorized Access Controls

Published: August 17, 2021

Affected versions
[*, 2.4.10)
Patched versions
2.4.10
Original Wordfence record
MediumCVE-2026-13253

Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block Attribute

Published: July 8, 2026

Affected versions
*-5.0.31
Patched versions
5.0.32
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory