Stored Cross-Site Scripting in GutenBee Plugin for WordPress
CVE-2025-8566
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 September 2025
What is CVE-2025-8566?
The GutenBee plugin for WordPress is susceptible to Stored Cross-Site Scripting vulnerabilities that arise from inadequate input sanitization and output escaping mechanisms. This weakness can be exploited by authenticated attackers, granted they have Contributor-level access or higher. Attackers can inject arbitrary scripts into pages via parameters in the CountUp and Google Maps Blocks. These malicious scripts are subsequently executed whenever a user accesses a compromised page, potentially leading to unauthorized access to sensitive information.
Affected Version(s)
GutenBee – Gutenberg Blocks * <= 2.18.0