PT-2026-33282 · Wpxpo · Post Grid Gutenberg Blocks For News

Published

2026-04-16

·

Updated

2026-04-16

·

CVE-2026-0718

CVSS v3.1

5.3

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ultp shareCount callback() function in all versions up to, and including, 5.0.5. This makes it possible for unauthenticated attackers to modify the share count post meta for any post, including private or draft posts.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-0718

Affected Products

Post Grid Gutenberg Blocks For News