GutenBee <= 2.20.1 - Authenticated (Author+) Arbitrary File Upload via wp_check_filetype_and_ext Filter
high
The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json function. This is due to a flawed strpos() substring check that only verifies whether the filename contains the string '.json' rather than confirmin...
- CVSS:
- 8.8
- Affected:
- up to 2.20.1
- Fixed in:
- 2.20.2
- Disclosed:
- May 27, 2026
CVE-2026-9227 on NVD →
GutenBee – Gutenberg Blocks <= 2.18.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters in the CountUp and Google Maps Blocks in all versions up to, and including, 2.18.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contrib...
- CVSS:
- 6.4
- Affected:
- up to 2.18.0
- Fixed in:
- 2.18.1
- Disclosed:
- Sep 29, 2025
CVE-2025-8566 on NVD →
GutenBee – Gutenberg Blocks [gutenbee] <= 2.18.0 (unfixed + closed)
unknown
- Affected:
- up to 2.18.0
- Fix:
- No patched version reported
CVE-2025-8566 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database