Stored Cross-Site Scripting Vulnerability in Getwid Plugin for WordPress
CVE-2026-91862
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-91862?
The Getwid β Gutenberg Blocks plugin for WordPress is susceptible to a stored cross-site scripting vulnerability via the 'data-image-points' parameter. This issue stems from inadequate input sanitization and output escaping in all versions up to and including 3.0.1. Authenticated attackers with contributor-level access or higher can exploit this flaw to inject arbitrary web scripts into web pages, which will execute every time a user visits a page containing the injected script, potentially compromising user data and site integrity.
Affected Version(s)
Getwid β Gutenberg Blocks 0 <= 3.0.1