CVE-2024-10728

Published
View on NVD ↗
CVSS v3
8.8
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up to, and including, 4.1.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

<p>🥇 The #1 WordPress news, magazine, and blogging solution<br /> 📈 Highest post grid layout variations with enhanced customization<br /> 💕 A plugin by <strong>WPXPO</strong>, that empowers <strong>65K+</strong> businesses!<br /> 📞 Dedicated support team with <strong>4.9/5</strong> customer satisfaction on <a href="https://uk.trustpilot.com/review/wpxpo.com" rel="nofollow ugc"><strong>Trustpilot</strong></a></p> <p>😲 <a href="https://trypostx.wpxpo.com/" rel="nofollow ugc"><strong>Free Demo</strong></a> | 🔥 <a href="https://www.wpxpo.com/product/postx/" rel="nofollow ugc"><strong>PostX Pro</strong></a> | 📃 <a href="https://www.wpxpo.com/product/postx/templates/" rel="nofollow ugc"><strong>Starter Templates</strong></a> | 📦 <a href="https://www.wpxpo.com/product/postx/features/blocks/" rel="nofollow ugc"><strong>All Blocks</strong></a></p> <h3>Ultimate Blog Website Builder for WordPress</h3> <p>Create modern news, magazine, and blog websites with advanced Gutenberg blocks, ready-made site templates, dynamic grid layouts, and advanced post filtering – all without coding.</p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/FYgSe7kgb6M?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <h3>Key Features of PostX</h3> <ul> <li>Ready-to-import starter sites to launch full blog websites in minutes.</li> <li>45+ advanced Gutenberg blocks for creating dynamic, content-rich layouts.</li> <li>250+ ready-made pattern designs to speed up page creation.</li> <li>Site builder to create custom templates for posts, categories, tags, authors, etc.</li> <li>Query builder to display posts by category, tag, author, custom taxonomy, or custom logic.</li> <li>Advanced post filtering, search, and pagination with Ajax for seamless browsing.</li> <li>Dynamic content support to pull data from custom fields, post meta, and custom post types.</li> <li>Global style settings to control colors, typography, and more across the entire site.</li> <li>Multi-column layouts and templates to create custom headers, footers, and mega menus.</li> <li>Advanced blogging tools such as table of contents, frontend post submission, and more.</li> <li>Built-in AI (ChatGPT) and SEO plugins integration for content creation</li> <li>Seamless integration with popular page builders such as Elementor, Divi, etc.</li> <li>Use custom fonts, dark mode, and more design options</li> <li>Mobile device responsive design &amp; multi-language support</li> <li>Performance optimized codebase</li> </ul> <h3>Starter Sites &#8211; Build Any Blog Website in 3 Steps!</h3> <p>Launch a fully designed blog website in minutes. With PostX starter sites, you can select a premade site template, customize it to match your brand, and go live – no need to spend hours manually creating every page!</p> <p><strong>👉 Check out the <a href="https://www.wpxpo.com/product/postx/templates/" rel="nofollow ugc">Starter Site Templates!</a></strong></p> <p>With PostX, you can easily build:</p> <p>✅ News Websites<br /> ✅ Magazine Websites<br /> ✅ Sports News Websites<br /> ✅ Tech News Websites<br /> ✅ Gaming News Websites<br /> ✅ Crypto News Websites<br /> ✅ Movie News Websites<br /> ✅ Travel Blog Websites<br /> ✅ Personal Blog Websites<br /> ✅ Food Blog Websites<br /> ✅ And More!</p> <p>👉 <strong>Step-by-step guide on creating a news blog website in WordPress using PostX:</strong></p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/xbOsCVvx1a0?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <h3>Gutenberg Blocks for Professional Blog Layouts</h3> <p>Get all the essential blocks to build a professional blog website. PostX blocks help you organize and design blog pages that are unique and visually engaging.</p> <p>✔ <strong>Post Grid:</strong> Showcase posts with 7+ cool grid layouts &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid6829" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>Post List:</strong> Present content in structured list formats &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid6836" rel="nofollow ugc">View Demo </a><br /> ✔ <strong>Post Slider &amp; Carousel:</strong> Highlight featured posts with interactive sliders &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid7487" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>Post Module:</strong> Display posts in structured, magazine-style layouts &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid6825" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>Mega Menu:</strong> Create advanced navigation menus &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid8819" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>Row/Column Block:</strong> Build structured layouts easily &#8211; <a href="https://www.wpxpo.com/product/postx/features/row-column-block/" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>Image Block:</strong> Style images with advanced controls &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid6843" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>News Ticker:</strong> Display trending posts dynamically &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid6845" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>Search Block:</strong> Ajax search for better navigation &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid8233" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>Star Rating:</strong> Add rating systems to highlight content &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid8858" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>Accordion Block:</strong> Display expandable content sections &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid8851" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>Button Group:</strong> Stylish CTA buttons for more engagement &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid7952" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>Taxonomy Block:</strong> Categories and tags in engaging designs &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid6841" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>Image Gallery Block:</strong> Create visually rich image sections &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid8951" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>Tabs Block:</strong> Organize blocks under tabs for improved visual &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid9045" rel="nofollow ugc">View Demo</a><br /> ✔ <strong>YouTube Gallery Block:</strong> Show video content in organized layouts &#8211; <a href="https://www.wpxpo.com/product/postx/features/blocks/#demoid9096" rel="nofollow ugc">View Demo</a><br /> ✔ <a href="https://www.wpxpo.com/product/postx/features/blocks/#site-cat-builder" rel="nofollow ugc"><strong>More 20+</strong></a> Dynamic builder block</p> <h3>Dynamic Gutenberg Site Builder</h3> <p>Design every part of your website exactly the way you want with PostX’s dynamic site builder. Create unique templates for specific pages to make them stand out – or maintain consistency with the same template.</p> <p>✔ Diverse layouts for category and tag pages<br /> ✔ Cool designs for archive Pages<br /> ✔ Custom blog post templates<br /> ✔ Custom Search &amp; date pages<br /> ✔ Custom 404 Not Found Pages<br /> ✔ Custom home page designs<br /> ✔ Custom author pages</p> <p><a href="https://www.wpxpo.com/product/postx/features/gutenberg-site-builder/" rel="nofollow ugc"><strong>👉 More about the</strong></a> Dynamic Site Builder</p> <h3>Query Builder for Enhanced Content Display</h3> <p>Choose exactly what content to show inside a section. Using the Quick Query feature, you can utilize advanced sorting options and customization options for maximum control over content display.</p> <p>Here is the list of essential post-displaying options:</p> <p>✔ Display Posts Based on Category<br /> ✔ Display Posts Based on Tags<br /> ✔ Display Specific Posts/Pages<br /> ✔ Display Posts from Specific Authors<br /> ✔ Display Custom Post Types<br /> ✔ Popular Posts<br /> ✔ Random Posts<br /> ✔ Oldest Posts<br /> ✔ Most Commented Posts<br /> ✔ Top Posts of the Month<br /> ✔ All-time Favorites<br /> ✔ Alphabetical ASC<br /> ✔ Alphabetical DESC<br /> ✔ Reorder Posts<br /> ✔ Exclude Posts</p> <p>And a lot of other options! 👉 <strong>Learn about <a href="https://www.wpxpo.com/product/postx/features/advanced-query-builder/" rel="nofollow ugc">Query Builder</a></strong></p> <h3>Advanced Post Filter</h3> <p>Let users easily filter and find the posts they are looking for – without reloading the whole page. You have all essential post-filtering options, including:</p> <p>✔ Filter By Ascending and Descending<br /> ✔ Filter By Custom Taxonomy<br /> ✔ Post Filter By Category<br /> ✔ Post Filter By Author<br /> ✔ Advanced Sort Filter<br /> ✔ Post Filter Tags<br /> ✔ Order By Filter<br /> ✔ Search Filter</p> <p>👉 <strong>Details about <a href="https://www.wpxpo.com/product/postx/features/wordpress-post-filter/" rel="nofollow ugc">Advanced Post Filter</a></strong></p> <h3>Ajax Pagination</h3> <p>Keep users engaged with seamless Ajax-powered pagination that loads content instantly without refreshing the page. PostX offers multiple pagination styles so you can choose what fits your website.</p> <p>✔ Load More pagination<br /> ✔ Numeric pagination<br /> ✔ Next/previous pagination</p> <p><strong>👉 Check out details for <a href="https://www.wpxpo.com/product/postx/features/ajax-pagination/" rel="nofollow ugc">Ajax Pagination</a></strong></p> <h3>Enhanced Blogging Features</h3> <p>Take your blog to the next level with advanced features designed to improve engagement, usability, and content management.</p> <p><a href="https://www.wpxpo.com/product/postx/features/front-end-post-submission/" rel="nofollow ugc"><strong>Front End Post Submission</strong></a><br /> Allow writers to submit content directly from the front end without giving them access to the WordPress dashboard. Perfect for managing guest and freelance writers.</p> <p><strong>Dynamic Content</strong><br /> Pull data dynamically from any post type and display information such as post meta, custom fields, and more.</p> <p><a href="https://www.wpxpo.com/product/postx/features/table-of-content-wordpress/" rel="nofollow ugc"><strong>Table of Contents</strong></a><br /> Add a structured table of contents to posts that improves readability and navigation – which also helps in SEO.</p> <p><a href="https://www.wpxpo.com/product/postx/features/reading-progress-bar/" rel="nofollow ugc"><strong>Reading Progress Bar</strong></a><br /> Show a visual progress bar on posts to highlight how much the visitor has read or scrolled. You can also add the progress bar to any page of your WordPress site.</p> <p><a href="https://www.wpxpo.com/product/postx/features/wordpress-taxonomy-image-and-color/" rel="nofollow ugc"><strong>Taxonomy Image &amp; Color</strong></a><br /> Add featured images and desired colors to categories, tags, and custom post types – making the taxonomies more visually appealing.</p> <h3>Header, Footer &amp; Mega Menu Builder</h3> <p>Improve your site’s navigation and direct visitors to highlighted sections of your site using fully customizable headers, footers, and mega menus.</p> <p>✔ A wide library of premade header and footer templates<br /> ✔ Option to create different headers/footers for different pages<br /> ✔ Build advanced mega menus with rich layouts, images, and content</p> <p><strong>Learn about:</strong> <a href="https://www.wpxpo.com/product/postx/features/mega-menu/" rel="nofollow ugc">PostX Mega menu</a><br /> <strong>Learn about:</strong> <a href="https://www.wpxpo.com/product/postx/features/header-footer-builder/" rel="nofollow ugc">PostX Header &amp; Footer</a></p> <h3>Premade Patterns</h3> <p>Speed up your blog creation with a library of ready-made designs.</p> <p>Instead of building sections from scratch, choose from professionally designed layouts and customize them to fit your brand.</p> <p><strong>Check out the live demo of <a href="https://www.wpxpo.com/product/postx/features/patterns/" rel="nofollow ugc">Premade Patterns.</a></strong></p> <h3>Blog Design &amp; Customization</h3> <p>Control the aesthetics of your entire blog effortlessly. Create a unique and consistent brand identity with global settings while having block-level control over designs.</p> <p><strong>Block-level Settings</strong><br /> Fine-tune every part of your blog layout with powerful styling controls built directly into each block. Easily switch between different layout variations, customize individual elements like title, image, meta, taxonomy, excerpt, and more.</p> <p><strong><a href="https://www.wpxpo.com/product/postx/features/wordpress-global-styles/" rel="nofollow ugc">Global Styles</a></strong><br /> Choose the colors and typography that you prefer and apply them globally across your website for a consistent look and feel.</p> <p><strong><a href="https://www.wpxpo.com/product/postx/features/custom-fonts-for-wordpress/" rel="nofollow ugc">Custom Fonts</a></strong><br /> Upload and use custom fonts that align with your brand guidelines. Use them with single or multiple variations – and use them inside PostX’s blocks with full typography customization options.</p> <p><strong>Dark Mode &amp; RTL Support</strong><br /> Give your readers a modern, eye-friendly experience with a built-in Light/Dark mode toggle. Also, we provide RTL support, which ensures a seamless reading experience for users who prefer right-to-left languages.</p> <h3>Integrations &amp; Compatibility</h3> <p>PostX works seamlessly with your favorite tools and enhances your blog management workflow.</p> <p><strong>AI Integration</strong><br /> Integrate with your ChatGPT account to easily create and optimize content directly inside WordPress.</p> <p><strong>Gutenberg Blocks in Page Builders</strong><br /> Love the comfort of your favorite page builders? Easily use Gutenberg blocks and any PostX-created designs directly inside popular page builders such as:</p> <p>✔ Elementor<br /> ✔ Divi<br /> ✔ WPBakery<br /> ✔ Oxygen<br /> ✔ Bricks Builder<br /> ✔ Beaver</p> <p>Design and reuse any set of designs with the help of the <a href="https://www.wpxpo.com/product/postx/features/saved-template/" rel="nofollow ugc">Saved Template</a> feature of PostX.</p> <h3>SEO Plugins Support</h3> <p>Fully compatible with major SEO plugins like Rank Math, Yoast, All-in-One SEO, Squirrly, SEOPress and others to display custom meta descriptions easily inside content.</p> <h3>PostX Recommended Themes</h3> <p>PostX should work properly with all popular WordPress themes. We have personally tested with various themes. Here is a list of themes that are fully compatible with PostX.</p> <p>✔ Twenty Twenty-Five<br /> ✔ Astra<br /> ✔ Blocksy<br /> ✔ Kadence<br /> ✔ Generatepress<br /> ✔ Rishi Theme<br /> ✔ Neve<br /> ✔ Ocean WP<br /> ✔ Blossom Theme<br /> ✔ Block WP</p> <h3>Upcoming Features</h3> <ul> <li>Dynamic Image Generation</li> <li>Infinite Scroll</li> <li>Icon Block</li> <li>Instagram Blocks</li> <li>Countdown Timer Blocks</li> </ul> <p><strong>Have a cool idea for a feature? Let us know: <a href="https://www.wpxpo.com/product/postx/roadmap/" rel="nofollow ugc">Request a feature</a></strong></p> <h3>Recommended by the WordPress Experts</h3> <p>Check out what Paul C (WPTuts) had to say about PostX.<br /> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/fh72g1wPVa0?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p> <p>Check out the video of Jack Cao and learn how to create a News Magazine Website for free.<br /> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/X4vKrjcSpI8?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p> <p>Check out how Alyssa creates a complete news website in minutes using PostX.<br /> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/s9w8Mt34_AQ?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p> <h3>Translations</h3> <p>PostX plugin is compatible with WPML Plugin and also it works perfectly with loco translate plugin.<br /> You can Translate PostX on <a href="https://translate.wordpress.org/projects/wp-plugins/ultimate-post/" rel="nofollow ugc">translate.wordpress.org</a>.</p> <h3>Liked PostX?</h3> <ul> <li>Join our <a href="https://www.facebook.com/groups/gutenbergpostx" rel="nofollow ugc">Facebook Group</a>.</li> <li>Learn from our tutorials on <a href="https://www.youtube.com/channel/UC9I7kzTtG31YlWdG3iL42Jg" rel="nofollow ugc">YouTube Channel</a>.</li> </ul> <h3>Author</h3> <p>Developed by <a href="https://www.wpxpo.com" rel="nofollow ugc">WPXPO</a>. <a href="https://bitbucket.org/wpstabon/ultimate-post/src/master/" rel="nofollow ugc">Contribute to Gutenberg Post Blocks on Bitbucket</a> and join the party.</p> <h3>Other Plugins by WPXPO</h3> <p>We are glad that you are considering PostX. We have more amazing plugins that you can check out:</p> <p>📄 <a href="https://wordpress.org/plugins/wow-pdf-invoices-packing-slips/" rel="ugc"><strong>WowInvoice 🔥:</strong></a> A comprehensive PDF invoices &amp; packing slips plugin for WooCommerce that automates documents like invoices, packing slips, and picklists.</p> <p>🚚 <a href="https://wordpress.org/plugins/wow-table-rate-shipping/" rel="ugc"><strong>WowShipping 🔥:</strong></a> The complete table rate shipping plugin for WooCommerce, featuring 30+ flexible conditions and integrations with popular carriers like UPS, USPS, DHL, Sendle, and more.</p> <p>➕ <a href="https://wordpress.org/plugins/product-addons/" rel="ugc"><strong>WowAddons 🔥 :</strong></a> The ultimate product addons plugin with 25+ extra product options, custom fields, allowing you to sell customizable products and increase average order v
WordPress Plugin DirectoryWordPress Plugin Directory
2.89M