Wpxpo develops WordPress plugins focused on content presentation and e-commerce functionality, including PostX for post-grid layouts, WholesaleX for bulk ordering, and WowStore for storefronts. Vulnerabilities affecting the vendor skew toward serious outcomes, concentrating in web-input handling and access-control weaknesses such as cross-site scripting, missing authorization checks, and deserialization flaws that are characteristic of PHP-based plugin architectures. Defenders should audit instances of these plugins for privilege-escalation and injection vectors; live severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpxpo over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-10728HIGH The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check | Nov 16, 2024 | 8.8 | 45 | NO | NO |
CVE-2025-69313HIGH Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PostX: from n/a through | Jan 22, 2026 | 7.5 | 27 | NO | NO |
CVE-2024-23512CRITICAL Deserialization of Untrusted Data vulnerability in wpxpo ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks.This issue affects ProductX – WooCommerce Builder & Gutenberg | Feb 12, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-30542CRITICAL Improper Privilege Management vulnerability in Wholesale WholesaleX allows Privilege Escalation.This issue affects WholesaleX: from n/a through 1.3.2. | May 17, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-30224CRITICAL Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.2. | Mar 28, 2024 | 9.8 | 25 | NO | NO |
CVE-2025-68606HIGH Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPXPO PostX ultimate-post allows Retrieve Embedded Sensitive Data.This issue affects Pos | Dec 24, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-31246HIGH Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PostX: from n/a through | Jun 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-30234HIGH Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1. | Mar 26, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-55707HIGH Incorrect Privilege Assignment vulnerability in WPXPO PostX ultimate-post allows Privilege Escalation.This issue affects PostX: from n/a through <= 4.1.35. | Dec 18, 2025 | 7.2 | 23 | NO | NO |
CVE-2025-54751HIGH Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PostX: from n/a through | Dec 18, 2025 | 7.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpxpo.
Media articles that mention a CVE ID that affects a product developed by Wpxpo — matched by CVE ID, not by vendor name.