CVE-2023-36385: WordPress PostX plugin <= 2.9.9 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX ultimate-post allows DOM-Based XSS.This issue affects PostX: from n/a through <= 2.9.9.
Other sources
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpxpo PostX – Gutenberg Post Grid Blocks plugin <= 2.9.9 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-36385.
What is the severity of CVE-2023-36385?
The severity of CVE-2023-36385 is high.
What is the affected software?
The affected software is the wpxpo PostX - Gutenberg Post Grid Blocks plugin with versions <= 2.9.9.
What is the description of CVE-2023-36385?
CVE-2023-36385 is an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the wpxpo PostX - Gutenberg Post Grid Blocks plugin.
Is there a patch or fix available for CVE-2023-36385?
Yes, a patch or fix is available for CVE-2023-36385. Please refer to the reference link for more information.