Stored Cross-Site Scripting in Gutentools Plugin for WordPress
CVE-2026-1395
6.4MEDIUM
What is CVE-2026-1395?
The Gutentools plugin for WordPress is vulnerable to a Stored Cross-Site Scripting attack through the Post Slider block's block_id attribute in all versions up to and including 1.1.3. This vulnerability arises from inadequate input sanitization and improper output escaping, compounded by a custom unescaping process that permits harmful characters to be reintroduced. As a result, authenticated users with Contributor-level access and above can exploit this flaw to insert arbitrary web scripts into pages, leading to script execution whenever a user visits the compromised page.
Affected Version(s)
Gutentools 0 <= 1.1.3