plugin

Gutenbee Vulnerabilities

3 known security issues reported for the Gutenbee WordPress plugin. Most recent disclosed May 27, 2026.

1 high 1 medium

Running Gutenbee on your site? Check whether your installed version is affected.

Scan your site free

GutenBee <= 2.20.1 - Authenticated (Author+) Arbitrary File Upload via wp_check_filetype_and_ext Filter

high

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json function. This is due to a flawed strpos() substring check that only verifies whether the filename contains the string '.json' rather than confirmin...

CVSS:
8.8
Affected:
up to 2.20.1
Fixed in:
2.20.2
Disclosed:
May 27, 2026

CVE-2026-9227 on NVD →

GutenBee – Gutenberg Blocks <= 2.18.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters in the CountUp and Google Maps Blocks in all versions up to, and including, 2.18.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contrib...

CVSS:
6.4
Affected:
up to 2.18.0
Fixed in:
2.18.1
Disclosed:
Sep 29, 2025

CVE-2025-8566 on NVD →

GutenBee &#8211; Gutenberg Blocks [gutenbee] <= 2.18.0 (unfixed + closed)

unknown
Affected:
up to 2.18.0
Fix:
No patched version reported

CVE-2025-8566 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database