vciy

CVEs we hold for Wpxpo

Records whose assigning authority named Wpxpo as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-57686WordPress WowAddons plugin <= 1.6.14 - Cross Site Scripting (XSS) vulnerabilityWPXPO WowAddons
CVE-2026-57377WordPress WowAddons plugin <= 1.6.8 - Broken Access Control vulnerabilityWPXPO WowAddons
CVE-2026-5158PostX <= 5.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comments Blockwpxpo Post Grid Gutenberg Blocks – PostX
CVE-2026-4302WowOptin: Next-Gen Popup Maker <= 1.4.29 - Unauthenticated Server-Side Request Forgery via 'link' Parameter in REST APIwpxpo WowOptin: Next-Gen Popup Maker – Create Stunning…
CVE-2026-39700WordPress WowOptin plugin <= 1.4.32 - Broken Access Control vulnerabilityWPXPO WowOptin
CVE-2026-2579WowStore – Store Builder & Product Blocks for WooCommerce <= 4.4.3 - Unauthenticated SQL Injection via 'search'…wpxpo WowStore – Store Builder & Product Blocks for…
CVE-2026-2518FastX <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation and Activationwpxpo FastX
CVE-2026-2001WowRevenue <= 2.1.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activationwpxpo WowRevenue – Product Bundles & Bulk Discounts
CVE-2026-1720WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation <= 1.4.24 - Missing…wpxpo WowOptin: Next-Gen Popup Maker – Create Stunning…
CVE-2026-17162WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'currentPostId' Block Attributewpxpo WowStore – Store Builder & Product Blocks for…
CVE-2026-17161WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'filterMobileText' Block Attributewpxpo WowStore – Store Builder & Product Blocks for…
CVE-2026-15100Post Grid Gutenberg Blocks <= 5.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'searchnoresult'…wpxpo Post Grid Gutenberg Blocks – PostX
CVE-2026-13253Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 - Authenticated (Contributor+) Stored…wpxpo Post Grid Gutenberg Blocks – PostX
CVE-2026-1273PostX <= 5.0.8 - Authenticated (Administrator+) Server-Side Request Forgery via REST API Endpointswpxpo Post Grid Gutenberg Blocks for News, Magazines, Blog…
CVE-2026-0718Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.5 - Missing Authorization to Limited Post…wpxpo Post Grid Gutenberg Blocks for News, Magazines, Blog…
CVE-2025-69313WordPress PostX plugin <= 5.0.3 - Broken Access Control vulnerabilityWPXPO PostX
CVE-2025-68606WordPress PostX plugin <= 5.0.3 - Sensitive Data Exposure vulnerabilityWPXPO PostX
CVE-2025-62070WordPress WowRevenue plugin <= 1.2.13 - Broken Access Control vulnerabilityWPXPO WowRevenue
CVE-2025-55707WordPress PostX Plugin <= 4.1.35 - Privilege Escalation VulnerabilityWPXPO PostX
CVE-2025-54751WordPress PostX plugin <= 4.1.36 - Broken Access Control vulnerabilityWPXPO PostX
CVE-2025-39571WordPress WowStore plugin <= 4.2.4 - Broken Access Control VulnerabilityWPXPO WowStore
CVE-2025-31096WordPress PostX plugin <= 4.1.25 - Cross Site Scripting (XSS) VulnerabilityWPXPO PostX
CVE-2025-12980Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.3 - Missing Authorization to…wpxpo Post Grid Gutenberg Blocks for News, Magazines, Blog…
CVE-2024-53818WordPress PostX plugin <= 4.1.15 - Cross Site Scripting (XSS) vulnerabilityWPXPO PostX
CVE-2024-5326Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 - Missing Authorization to Arbitrary Options…wpxpo Post Grid Gutenberg Blocks for News, Magazines, Blog…
CVE-2024-5223Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.1 - Authenticated (Author+) Stored Cross-Site…wpxpo Post Grid Gutenberg Blocks for News, Magazines, Blog…
CVE-2024-50513WordPress PostX plugin <= 4.1.15 - Cross Site Scripting (XSS) vulnerabilityWPXPO PostX
CVE-2024-50443WordPress PostX plugin <= 4.1.12 - Cross Site Scripting (XSS) vulnerabilityWPXPO PostX
CVE-2024-32564WordPress PostX plugin <= 4.0.1 - Cross Site Scripting (XSS) vulnerabilityWPXPO PostX
CVE-2024-31246WordPress PostX plugin <= 3.2.3 - Author+ Post/Page Duplication vulnerabilityWPXPO PostX
CVE-2024-23512WordPress ProductX – Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object Injectionwpxpo ProductX – WooCommerce Builder & Gutenberg…
CVE-2024-10728PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/Activationwpxpo Post Grid Gutenberg Blocks for News, Magazines, Blog…
CVE-2023-45271WordPress ProductX – Gutenberg WooCommerce Blocks plugin <= 2.7.8 - Broken Access Control vulnerabilityWPXPO WowStore
CVE-2023-36385WordPress PostX – Gutenberg Blocks for Post Grid Plugin <= 2.9.9 is vulnerable to Cross Site Scripting (XSS)wpxpo PostX – Gutenberg Post Grid Blocks

34 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.