Stored Cross-Site Scripting Vulnerability in Gutenverse Plugin for WordPress
CVE-2026-19943
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-19943?
The Gutenverse plugin for WordPress suffers from Stored Cross-Site Scripting vulnerabilities due to inadequate sanitization and escaping of the 'titleTag' block attribute. This flaw allows authenticated users, such as contributors or higher, to insert malicious scripts into pages, which will execute when any user accesses affected content. The harmful scripts remain intact even during the saving process, as they are enclosed within a block-comment delimiter, resulting in potential execution in administration or editor environments during post previews.
Affected Version(s)
Gutenverse β WordPress Blocks, Page Builder & Site Editor 0 <= 4.0.2