What is CVE-2026-5158?
This vulnerability is a Stored Cross-Site Scripting (XSS) issue in the PostX plugin for WordPress, caused by insufficient sanitization of the 'inputPlaceHolder' parameter. Authenticated users can inject malicious scripts, affecting all versions up to 5.0.13. Users should immediately update to the latest patched version.
Azərbaycanca: Bu zəiflik WordPress üçün PostX plaginində saxlanılan XSS (Stored Cross-Site Scripting) problemidir. 'inputPlaceHolder' parametrinin kifayət qədər təmizlənməməsi səbəbindən autentifikasiya olunmuş istifadəçilər zərərli skript yerləşdirə bilər. Plagindən istifadə edənlər dərhal ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
How does CVE-2026-5158 affect the PostX plugin for WordPress?
It is a Stored XSS vulnerability caused by insufficient sanitization of the 'inputPlaceHolder' parameter. Authenticated users can inject malicious scripts.
What should PostX plugin users do to protect against CVE-2026-5158?
Users should immediately update to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.