Stored Cross-Site Scripting Vulnerability in Gutenverse Plugin for WordPress
CVE-2026-19943

6.4MEDIUM

What is CVE-2026-19943?

The Gutenverse plugin for WordPress suffers from Stored Cross-Site Scripting vulnerabilities due to inadequate sanitization and escaping of the 'titleTag' block attribute. This flaw allows authenticated users, such as contributors or higher, to insert malicious scripts into pages, which will execute when any user accesses affected content. The harmful scripts remain intact even during the saving process, as they are enclosed within a block-comment delimiter, resulting in potential execution in administration or editor environments during post previews.

Affected Version(s)

Gutenverse – WordPress Blocks, Page Builder & Site Editor 0 <= 4.0.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.