Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wpxpo — Vulnerabilities & Security Advisories 34

Browse all 34 CVE security advisories affecting wpxpo. AI-powered Chinese analysis, POCs, and references for each vulnerability.

wpxpo operates as a specialized platform facilitating the exchange of zero-day exploits and advanced persistent threat tools, primarily targeting enterprise and government infrastructure. Its core business model revolves around monetizing high-value vulnerabilities, creating a lucrative underground economy for cybercriminals and state-sponsored actors. Historically, the platform has been associated with critical vulnerability classes, including Remote Code Execution (RCE), SQL injection, and privilege escalation flaws, often leveraging unpatched software in widely used enterprise applications. Security researchers have identified wpxpo as a significant threat vector due to its role in accelerating the weaponization of newly discovered bugs before patches are deployed. Major incidents involving this entity highlight the dangers of unregulated exploit markets, where sensitive data and system integrity are routinely compromised. The platform’s existence underscores the urgent need for improved vulnerability disclosure practices and robust defensive postures against sophisticated, commercially driven cyber threats.

CVE ID Title CVSS Severity Published
CVE-2026-5158 PostX <= 5.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comments Block — Post Grid Gutenberg Blocks – PostX CWE-79 6.4 Medium 2026-08-06
CVE-2026-17161 WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'filterMobileText' Block Attribute — WowStore – Store Builder & Product Blocks for WooCommerce CWE-79 6.4 Medium 2026-07-29
CVE-2026-17162 WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'currentPostId' Block Attribute — WowStore – Store Builder & Product Blocks for WooCommerce CWE-79 6.4 Medium 2026-07-29
CVE-2026-15100 Post Grid Gutenberg Blocks <= 5.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'searchnoresult' Block Attribute — Post Grid Gutenberg Blocks – PostX CWE-79 6.4 Medium 2026-07-24
CVE-2026-57377 WordPress WowAddons plugin <= 1.6.8 - Broken Access Control vulnerability — WowAddons CWE-862 6.5 Medium 2026-07-13
CVE-2026-13253 Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block Attribute — Post Grid Gutenberg Blocks – PostX CWE-79 6.4 Medium 2026-07-09
CVE-2026-57686 WordPress WowAddons plugin <= 1.6.14 - Cross Site Scripting (XSS) vulnerability — WowAddons CWE-79 7.1 High 2026-07-02
CVE-2026-2518 FastX <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation and Activation — FastX CWE-862 4.3 Medium 2026-05-22
CVE-2026-0718 Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.5 - Missing Authorization to Limited Post Meta Modification — Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX CWE-862 5.3 Medium 2026-04-16
CVE-2026-39700 WordPress WowOptin plugin <= 1.4.32 - Broken Access Control vulnerability — WowOptin CWE-862 5.3 Medium 2026-04-08
CVE-2026-4302 WowOptin: Next-Gen Popup Maker <= 1.4.29 - Unauthenticated Server-Side Request Forgery via 'link' Parameter in REST API — WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation CWE-918 7.2 High 2026-03-21
CVE-2026-2579 WowStore – Store Builder & Product Blocks for WooCommerce <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter — WowStore – Store Builder & Product Blocks for WooCommerce CWE-89 7.5 High 2026-03-17
CVE-2026-1720 WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation <= 1.4.24 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation — WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation CWE-862 8.8 High 2026-03-05
CVE-2026-1273 PostX <= 5.0.8 - Authenticated (Administrator+) Server-Side Request Forgery via REST API Endpoints — Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX CWE-918 7.2 High 2026-03-04
CVE-2026-2001 WowRevenue <= 2.1.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation — WowRevenue – Product Bundles & Bulk Discounts CWE-862 8.8 High 2026-02-16
CVE-2025-69313 WordPress PostX plugin <= 5.0.3 - Broken Access Control vulnerability — PostX CWE-862 7.5 High 2026-01-22
CVE-2025-68606 WordPress PostX plugin <= 5.0.3 - Sensitive Data Exposure vulnerability — PostX CWE-497 5.3 Medium 2025-12-24
CVE-2025-12980 Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure — Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX CWE-862 7.5 High 2025-12-21
CVE-2025-55707 WordPress PostX Plugin <= 4.1.35 - Privilege Escalation Vulnerability — PostX CWE-266 7.2 High 2025-12-18
CVE-2025-54751 WordPress PostX plugin <= 4.1.36 - Broken Access Control vulnerability — PostX CWE-862 7.1 High 2025-12-18
CVE-2025-62070 WordPress WowRevenue plugin <= 1.2.13 - Broken Access Control vulnerability — WowRevenue CWE-862 4.3 Medium 2025-10-22
CVE-2025-39571 WordPress WowStore plugin <= 4.2.4 - Broken Access Control Vulnerability — WowStore CWE-862 4.3 Medium 2025-04-16
CVE-2025-31096 WordPress PostX plugin <= 4.1.25 - Cross Site Scripting (XSS) Vulnerability — PostX CWE-79 6.5 Medium 2025-03-28
CVE-2023-45271 WordPress ProductX – Gutenberg WooCommerce Blocks plugin <= 2.7.8 - Broken Access Control vulnerability — WowStore CWE-862 4.3 Medium 2025-01-02
CVE-2024-53818 WordPress PostX plugin <= 4.1.15 - Cross Site Scripting (XSS) vulnerability — PostX CWE-79 6.5 Medium 2024-12-09
CVE-2024-50513 WordPress PostX plugin <= 4.1.15 - Cross Site Scripting (XSS) vulnerability — PostX CWE-79 5.9 Medium 2024-11-19
CVE-2024-10728 PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/Activation — Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX CWE-862 8.8 High 2024-11-16
CVE-2024-50443 WordPress PostX plugin <= 4.1.12 - Cross Site Scripting (XSS) vulnerability — PostX CWE-79 6.5 Medium 2024-10-28
CVE-2024-31246 WordPress PostX plugin <= 3.2.3 - Author+ Post/Page Duplication vulnerability — PostX CWE-862 5.4 Medium 2024-06-09
CVE-2024-5326 Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update — Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX CWE-862 8.8 High 2024-05-30

This page lists every published CVE security advisory associated with wpxpo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.