Jegstudio Vulnerabilities and Affected Products
Vulnerabilities associated with Gutenverse.
Products
Clear product- Gutenverse5 vulnerabilities
- Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem5 vulnerabilities
- Gutenverse Companion2 vulnerabilities
- Gutenverse Form2 vulnerabilities
- Gutenverse – WordPress Blocks, Page Builder & Site Editor2 vulnerabilities
- Financio1 vulnerability
- Gutenverse Form – Contact Form Builder, Booking, Reservation, Subscribe for Block Editor1 vulnerability
- Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons1 vulnerability
- Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons1 vulnerability
- Startupzy1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-66065MEDIUM | WordPress Gutenverse plugin <= 3.2.1 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Jegstudio Gutenverse gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse: from n/a through <= 3.2.1. CWE-862Nov 21, 2025 | CVSS6.5v3.1 | EPSS0.239% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-35875MEDIUM | WordPress Gutenverse – Gutenberg Blocks – Page Builder for Site Editor plugin <= 1.8.5 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Jegstudio Gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse: from n/a through 1.8.5. CWE-862Dec 13, 2024 | CVSS5.3v3.1 | EPSS0.577% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43920MEDIUM | WordPress Gutenverse – Gutenberg Blocks – Page Builder for Site Editor plugin <= 1.9.4 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: from n/a through 1.9.4. CWE-79Aug 29, 2024 | CVSS6.5v3.1 | EPSS0.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38785MEDIUM | WordPress Gutenverse plugin <= 1.9.2 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: from n/a through 1.9.2. CWE-79Jul 21, 2024 | CVSS6.5v3.1 | EPSS0.254% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-3692MEDIUM | Gutenverse < 1.9.1 - Contributor+ Stored XSSThe Gutenverse WordPress plugin before 1.9.1 does not validate the htmlTag option in various of its block before outputting it back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks CWE-79May 3, 2024 | CVSS6.1v3.1 | EPSS0.442% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |