Showing 2 vulnerabilities on this page for Gutenverse – WordPress Blocks, Page Builder & Site Editor

Signals CISA KEV Ransomware Nuclei
Jegstudio vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Gutenverse <= 3.8.0 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fonts[].font.font.value' Parameter

The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and install

CWE-79Jun 27, 2026
CVSS4.4v3.1EPSS0.244%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Gutenverse <= 3.4.6 - Reflected Cross-Site Scripting via 's' Parameter

The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. Specifically, the `render_content()` method in `class-search-result-title.php` outputs the value of `get_query_var('s')` directly into the page HTML without applying `esc_html()` or any other escaping function. This makes it possible for unauthenticated attackers to inject arbitrary web sc

CWE-79May 27, 20261 related artifact
CVSS6.1v3.1EPSS0.204%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX