Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML
medium
The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...
- CVSS:
- 5.4
- Affected:
- up to 3.5.5
- Fixed in:
- 3.5.6
- Disclosed:
- Apr 22, 2026
CVE-2026-2951 on NVD →
Gutentor <= 3.5.2 - Missing Authorization
medium
The Gutentor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.5.2. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 5.4
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.3
- Disclosed:
- Sep 22, 2025
CVE-2025-58680 on NVD →
Gutentor <= 3.5.5 - Missing Authorization
medium
The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to perfo...
- CVSS:
- 4.3
- Affected:
- up to 3.5.5
- Fixed in:
- 3.5.6
- Disclosed:
- Sep 5, 2025
CVE-2025-58783 on NVD →
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor [gutentor] <= 3.5.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in gutentor Gutentor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Gutentor: from n/a through 3.5.1.
- Affected:
- up to 3.5.1
- Fix:
- No patched version reported
- Disclosed:
- Sep 5, 2025
CVE-2025-58783 on NVD →
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML data attributes of multiple widgets, in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authe...
- CVSS:
- 6.4
- Affected:
- up to 3.4.8
- Fixed in:
- 3.4.9
- Disclosed:
- Jul 20, 2025
CVE-2025-4685 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 3.4.9
- Fix:
- No patched version reported
- Disclosed:
- Jul 2, 2025
CVE-2024-5647 on NVD →
Gutentor <= 3.4.6 - Authenticated (Administrator+) SQL Injection
medium
The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authen...
- CVSS:
- 4.9
- Affected:
- up to 3.4.6
- Fixed in:
- 3.4.7
- Disclosed:
- Mar 11, 2025
CVE-2025-1986 on NVD →
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor [gutentor] < 3.4.4 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gutentor Gutentor allows DOM-Based XSS.This issue affects Gutentor: from n/a through 3.4.0.
- Affected:
- up to 3.4.4
- Fixed in:
- 3.4.4
- Disclosed:
- Jan 7, 2025
CVE-2025-22293 on NVD →
Gutentor <= 3.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Gutentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.4
- Disclosed:
- Jan 6, 2025
CVE-2025-22293 on NVD →
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor [gutentor] < 3.4.0 (closed)
unknown
[en] The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p...
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.0
- Disclosed:
- Dec 5, 2024
CVE-2024-10178 on NVD →
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
medium
The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib...
- CVSS:
- 6.4
- Affected:
- up to 3.3.9
- Fixed in:
- 3.4.0
- Disclosed:
- Dec 4, 2024
CVE-2024-10178 on NVD →
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor [gutentor] < 3.3.6 (closed)
unknown
[en] The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 3.3.6
- Fixed in:
- 3.3.6
- Disclosed:
- Aug 29, 2024
CVE-2024-5417 on NVD →
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor [gutentor] < 3.3.6 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gutentor Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor allows Stored XSS.This issue affects Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor: from n/a through 3.3.5.
- Affected:
- up to 3.3.6
- Fixed in:
- 3.3.6
- Disclosed:
- Aug 18, 2024
CVE-2024-43308 on NVD →
Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...
- CVSS:
- 6.4
- Affected:
- up to 3.3.5
- Fixed in:
- 3.3.6
- Disclosed:
- Aug 16, 2024
CVE-2024-43308 on NVD →
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor [gutentor] < 1.0.3 (closed)
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.3
CVE-2023-33999 on NVD →
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor [gutentor] < 3.4.7 (closed)
unknown
- Affected:
- up to 3.4.7
- Fixed in:
- 3.4.7
CVE-2025-1986 on NVD →
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor [gutentor] <= 3.4.9 (unfixed + closed)
unknown
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...
- Affected:
- up to 3.4.9
- Fix:
- No patched version reported
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor [gutentor] < 3.4.9 (closed)
unknown
- Affected:
- up to 3.4.9
- Fixed in:
- 3.4.9
CVE-2025-4685 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database