plugin

Gutentor Vulnerabilities

18 known security issues reported for the Gutentor WordPress plugin. Most recent disclosed Apr 22, 2026.

9 medium

Running Gutentor on your site? Check whether your installed version is affected.

Scan your site free

Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML

medium

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...

CVSS:
5.4
Affected:
up to 3.5.5
Fixed in:
3.5.6
Disclosed:
Apr 22, 2026

CVE-2026-2951 on NVD →

Gutentor <= 3.5.2 - Missing Authorization

medium

The Gutentor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.5.2. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

CVSS:
5.4
Affected:
up to 3.5.2
Fixed in:
3.5.3
Disclosed:
Sep 22, 2025

CVE-2025-58680 on NVD →

Gutentor <= 3.5.5 - Missing Authorization

medium

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to perfo...

CVSS:
4.3
Affected:
up to 3.5.5
Fixed in:
3.5.6
Disclosed:
Sep 5, 2025

CVE-2025-58783 on NVD →

Gutentor &#8211; Gutenberg Blocks &#8211; Page Builder for Gutenberg Editor [gutentor] <= 3.5.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in gutentor Gutentor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Gutentor: from n/a through 3.5.1.

Affected:
up to 3.5.1
Fix:
No patched version reported
Disclosed:
Sep 5, 2025

CVE-2025-58783 on NVD →

Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

medium

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML data attributes of multiple widgets, in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authe...

CVSS:
6.4
Affected:
up to 3.4.8
Fixed in:
3.4.9
Disclosed:
Jul 20, 2025

CVE-2025-4685 on NVD →

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library

medium

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...

CVSS:
6.4
Affected:
up to 3.4.9
Fix:
No patched version reported
Disclosed:
Jul 2, 2025

CVE-2024-5647 on NVD →

Gutentor <= 3.4.6 - Authenticated (Administrator+) SQL Injection

medium

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authen...

CVSS:
4.9
Affected:
up to 3.4.6
Fixed in:
3.4.7
Disclosed:
Mar 11, 2025

CVE-2025-1986 on NVD →

Gutentor &#8211; Gutenberg Blocks &#8211; Page Builder for Gutenberg Editor [gutentor] < 3.4.4 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gutentor Gutentor allows DOM-Based XSS.This issue affects Gutentor: from n/a through 3.4.0.

Affected:
up to 3.4.4
Fixed in:
3.4.4
Disclosed:
Jan 7, 2025

CVE-2025-22293 on NVD →

Gutentor <= 3.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Gutentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
6.4
Affected:
up to 3.4.3
Fixed in:
3.4.4
Disclosed:
Jan 6, 2025

CVE-2025-22293 on NVD →

Gutentor &#8211; Gutenberg Blocks &#8211; Page Builder for Gutenberg Editor [gutentor] < 3.4.0 (closed)

unknown

[en] The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p...

Affected:
up to 3.4.0
Fixed in:
3.4.0
Disclosed:
Dec 5, 2024

CVE-2024-10178 on NVD →

Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

medium

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib...

CVSS:
6.4
Affected:
up to 3.3.9
Fixed in:
3.4.0
Disclosed:
Dec 4, 2024

CVE-2024-10178 on NVD →

Gutentor &#8211; Gutenberg Blocks &#8211; Page Builder for Gutenberg Editor [gutentor] < 3.3.6 (closed)

unknown

[en] The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 3.3.6
Fixed in:
3.3.6
Disclosed:
Aug 29, 2024

CVE-2024-5417 on NVD →

Gutentor &#8211; Gutenberg Blocks &#8211; Page Builder for Gutenberg Editor [gutentor] < 3.3.6 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gutentor Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor allows Stored XSS.This issue affects Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor: from n/a through 3.3.5.

Affected:
up to 3.3.6
Fixed in:
3.3.6
Disclosed:
Aug 18, 2024

CVE-2024-43308 on NVD →

Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...

CVSS:
6.4
Affected:
up to 3.3.5
Fixed in:
3.3.6
Disclosed:
Aug 16, 2024

CVE-2024-43308 on NVD →

Gutentor &#8211; Gutenberg Blocks &#8211; Page Builder for Gutenberg Editor [gutentor] < 1.0.3 (closed)

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.0.3
Fixed in:
1.0.3

CVE-2023-33999 on NVD →

Gutentor &#8211; Gutenberg Blocks &#8211; Page Builder for Gutenberg Editor [gutentor] < 3.4.7 (closed)

unknown
Affected:
up to 3.4.7
Fixed in:
3.4.7

CVE-2025-1986 on NVD →

Gutentor &#8211; Gutenberg Blocks &#8211; Page Builder for Gutenberg Editor [gutentor] <= 3.4.9 (unfixed + closed)

unknown

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin&#039;s bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...

Affected:
up to 3.4.9
Fix:
No patched version reported

Gutentor &#8211; Gutenberg Blocks &#8211; Page Builder for Gutenberg Editor [gutentor] < 3.4.9 (closed)

unknown
Affected:
up to 3.4.9
Fixed in:
3.4.9

CVE-2025-4685 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database