Stored Cross-Site Scripting Vulnerability in Gutenverse Plugin for WordPress
CVE-2026-12399
4.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 June 2026
What is CVE-2026-12399?
The Gutenverse plugin for WordPress, affecting all versions up to and including 3.8.0, is susceptible to a stored cross-site scripting issue due to inadequate input sanitization and output escaping within admin settings. This vulnerability allows authenticated attackers with editor-level permissions or higher to inject malicious web scripts into pages. When a user accesses an affected page, the injected scripts execute, posing a risk particularly in multi-site setups and when the unfiltered_html configuration is disabled.
Affected Version(s)
Gutenverse β WordPress Blocks, Page Builder & Site Editor 0 <= 3.8.0