PatchSiren

wpxpo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM wpxpo CVE published 2026-08-06

CVE-2026-5158

The PostX plugin for WordPress, specifically versions up to and including 5.0.13, is vulnerable to Stored Cross-Site Scripting via the 'inputPlaceHolder' parameter. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts into pages, which will execute when a user accesses an injected page. The vulnerability is due to insufficient input sani [truncated]

MEDIUM WPXPO CVE published 2026-07-13

CVE-2026-57377

A Missing Authorization vulnerability was found in WPXPO WowAddons product-addons, allowing Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WowAddons from n/a through <= 1.6.8. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Users of WPXPO WowAddons product-addons, especially those with versions from n/a through <= 1.6.8, should be aware [truncated]

MEDIUM wpxpo CVE published 2026-05-22

CVE-2026-2518

CVE-2026-2518 is an authorization weakness in the FastX WordPress theme. Because the theme’s ultp_install_callback and ultp_activate_callback functions lack capability checks, authenticated users with Subscriber-level access and above can install and activate the PostX plugin. The issue affects FastX versions up to and including 1.0.2 and is rated Medium severity (CVSS 4.3).

MEDIUM WPXPO CVE published 2026-04-08

CVE-2026-39700

CVE-2026-39700 is a Missing Authorization vulnerability in WPXPO WowOptin optin. The issue allows Exploiting Incorrectly Configured Access Control Security Levels and affects WowOptin from n/a through <= 1.4.32. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. This issue may impact users of WPXPO WowOptin optin version 1.4.32 or earlier. Affected deployments should be identified and patched.