Stored Cross-Site Scripting in Gutenberg Essential Blocks Page Builder for WordPress
CVE-2025-11270
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 October 2025
What is CVE-2025-11270?
The Gutenberg Essential Blocks plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability, where insufficient input sanitization and escaping of the 'titleTag' attribute allows authenticated attackers with Contributor-level access and higher to inject arbitrary web scripts. This vulnerability compromises user security by executing the scripts whenever a page is accessed, posing significant risks to site integrity.
Affected Version(s)
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns * <= 5.7.1