plugin

Gutenberg Vulnerabilities

26 known security issues reported for the Gutenberg WordPress plugin. Most recent disclosed Oct 31, 2025.

1 high 12 medium

Running Gutenberg on your site? Check whether your installed version is affected.

Scan your site free

Gutenberg [gutenberg] < 21.9.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gutenberg gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through <= 21.8.2.

Affected:
up to 21.9.0
Fixed in:
21.9.0
Disclosed:
Oct 31, 2025

CVE-2025-64354 on NVD →

Gutenberg <= 21.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 21.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 21.8.2
Fixed in:
21.9.0
Disclosed:
Oct 25, 2025

CVE-2025-64354 on NVD →

Gutenberg 21.7 - 21.8 - Contributor+ Stored XSS

medium
Affected:
21.7 – 21.9.0
Fixed in:
21.9.0
Disclosed:
Oct 25, 2025

CVE-2025-64354 on NVD →

Gutenberg [gutenberg] < 18.6.1

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gutenberg Team Gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through 18.6.0.

Affected:
up to 18.6.1
Fixed in:
18.6.1
Disclosed:
Jul 21, 2024

CVE-2024-37492 on NVD →

WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Template Part Block

medium

WordPress Core is vulnerable to Stored Cross-Site Scripting via the Template Part Block in various versions up to 6.5.5 due to insufficient input sanitization and output escaping on the 'tagName' attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary...

CVSS:
6.4
Affected:
up to 18.6.0
Fixed in:
18.6.1
Disclosed:
Jun 24, 2024

CVE-2024-31111 on NVD →

WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Template Part Block

medium
Affected:
up to 18.6.1
Fixed in:
18.6.1
Disclosed:
Jun 24, 2024

CVE-2024-31111 on NVD →

Gutenberg 12.9.0 - 18.0.0 - Unauthenticated & Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block

medium

The Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in versions 12.9.0 to 18.0.0 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrar...

CVSS:
6.4
Affected:
12.9.0 – 18.0.0
Fixed in:
18.01
Disclosed:
Apr 9, 2024

Gutenberg 12.9.0 - 18.0.0 - Unauthenticated & Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block

high
Affected:
up to 18.01
Fixed in:
18.01
Disclosed:
Apr 9, 2024

Gutenberg [gutenberg] >= 12.9.0 - <= 18.0.0

unknown

The Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in versions 12.9.0 to 18.0.0 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrar...

Affected:
12.9.0 – 18.0.0
Fixed in:
18.0.0
Disclosed:
Apr 9, 2024

Gutenberg < 16.8.1 - Contributor+ Stored XSS

medium
Affected:
16.1 – 16.8.1
Fixed in:
16.8.1
Disclosed:
Nov 17, 2023

Gutenberg < 16.8.1 - Contributor+ Stored XSS via Navigation Links Block

medium
Affected:
up to 16.8.1
Fixed in:
16.8.1
Disclosed:
Oct 13, 2023

CVE-2023-38000 on NVD →

Gutenberg [gutenberg] < 16.8.1

unknown

[en] Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.

Affected:
up to 16.8.1
Fixed in:
16.8.1
Disclosed:
Oct 13, 2023

CVE-2023-38000 on NVD →

WordPress Core 5.9-6.3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Navigation Attributes

medium

WordPress Core is vulnerable to Stored Cross-Site Scripting via the arrow navigation block attributes in versions between 5.9 and 6.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level privileges and above to inject arbitrary web scrip...

CVSS:
6.4
Affected:
up to 16.8.0
Fixed in:
16.8.1
Disclosed:
Oct 12, 2023

CVE-2023-38000 on NVD →

WordPress Core < 6.0.3 & Gutenberg < 14.3.1 - Authenticated Cross-Site Scripting in Various Blocks

medium

WordPress Core in versions up to 6.0.3 and the Gutenberg plugin for WordPress in versions up to 14.3.1 are vulnerable to Stored Cross-Site Scripting due to insufficient output escaping on user supplied input. The RSS widget, Search Block, Featured Image Block, RSS Block, and Navigation Block are all affected components...

CVSS:
6.4
Affected:
up to 14.3.0
Fixed in:
14.3.1
Disclosed:
Oct 18, 2022

CVE-2022-43500 on NVD →

Gutenberg [gutenberg] < 14.3.1

unknown

Multiple Stored Cross-Site Scripting (XSS) vulnerabilities via Search, Feature Image, RSS, and Widget blocks were discovered by Alex Concha (WP Security team) and a third-party audit in the WordPress Gutenberg plugin (versions <= 14.3.1). Update the WordPress Gutenberg plugin to the latest available version (at least 1...

Affected:
up to 14.3.1
Fixed in:
14.3.1
Disclosed:
Oct 18, 2022

Gutenberg [gutenberg] < 14.3.1

unknown

WordPress Core in versions up to 6.0.3 and the Gutenberg plugin for WordPress in versions up to 14.3.1 are vulnerable to Stored Cross-Site Scripting due to insufficient output escaping on user supplied input. The RSS widget, Search Block, Featured Image Block, RSS Block, and Navigation Block are all affected components...

Affected:
up to 14.3.1
Fixed in:
14.3.1
Disclosed:
Oct 18, 2022

Gutenberg < 14.3.1 - Multiple Stored XSS

medium
Affected:
up to 14.3.1
Fixed in:
14.3.1
Disclosed:
Oct 17, 2022

Gutenberg [gutenberg] <= 17.3.0 (unfixed)

unknown

[en] The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress instance's domain; however, analogous attempts by low-privileged users to reference SVG documents...

Affected:
up to 17.3.0
Fix:
No patched version reported
Disclosed:
Jul 30, 2022

CVE-2022-33994 on NVD →

WordPress Core < 5.9.2 & Gutenberg < 12.7.2 - Prototype Pollution via Block Editor

medium

WordPress Core in various versions < 5.9.2 and Gutenberg versions less than 12.7.2 are vulnerable to prototype pollution via the block editor which could make injecting malicious web scripts possible in some cases.

CVSS:
5.4
Affected:
up to 12.7.2
Fixed in:
12.7.2
Disclosed:
Mar 11, 2022

WordPress < 5.9.2 / Gutenberg < 12.7.2 - Prototype Pollution via Gutenberg’s wordpress/url package

unknown
Affected:
up to 12.7.2
Fixed in:
12.7.2
Disclosed:
Mar 11, 2022

Gutenberg [gutenberg] < 12.7.2

unknown

WordPress Core in various versions < 5.9.2 and Gutenberg versions less than 12.7.2 are vulnerable to prototype pollution via the block editor which could make injecting malicious web scripts possible in some cases.

Affected:
up to 12.7.2
Fixed in:
12.7.2
Disclosed:
Mar 11, 2022

Gutenberg [gutenberg] < 12.7.2

unknown

Stored Cross-Site Scripting (XSS) vulnerability discovered by Ben Bidner in WordPress Gutenberg plugin (versions <= 12.7.1).

Affected:
up to 12.7.2
Fixed in:
12.7.2
Disclosed:
Mar 11, 2022

WordPress (5.9-5.9.1) / Gutenberg (9.8.0-12.7.1) - Contributor+ Stored Cross-Site Scripting

medium
Affected:
9.8.0 – 12.7.2
Fixed in:
12.7.2
Disclosed:
Mar 11, 2022

Gutenberg [gutenberg] < 14.3.1

unknown

The plugin does not escape data from some blocks before outputting ti back in pages, which could lead to Stored XSS issues. Affected blocks: Search, Feature Image, RSS and Widget

Affected:
up to 14.3.1
Fixed in:
14.3.1

Gutenberg [gutenberg] < 16.8.1

unknown

The plugin does not adequately escape the content of the footnotes within the paragraph block of the block editor, leading to a Contributor+ Cross-Site Scripting vulnerability.

Affected:
up to 16.8.1
Fixed in:
16.8.1

Gutenberg [gutenberg] >= 12.9.0 - <= 18.0.0

unknown

Update the WordPress Gutenberg plugin to the latest available version (at least 18.1.0). John Blackbourn discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gutenberg Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML...

Affected:
12.9.0 – 18.0.0
Fixed in:
18.0.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database