CVE-2026-92746
- EPSS 0.19%
- Veröffentlicht 25.09.2026 06:39:57
- Zuletzt bearbeitet 25.09.2026 14:17:22
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute in all versions up to, and including, 4.0.8 due to insufficient input saniti...
CVE-2026-3002
- EPSS 0.26%
- Veröffentlicht 26.08.2026 06:08:27
- Zuletzt bearbeitet 26.08.2026 16:19:05
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output ...
CVE-2026-19943
- EPSS 0.2%
- Veröffentlicht 25.08.2026 03:27:07
- Zuletzt bearbeitet 26.08.2026 16:19:05
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'titleTag' Block Attribute in all versions up to, and including, 4.0.2 due to insufficient input sanitization and outp...
CVE-2026-12399
- EPSS 0.24%
- Veröffentlicht 27.06.2026 06:50:59
- Zuletzt bearbeitet 29.06.2026 18:40:23
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping....
CVE-2026-54832
- EPSS 0.24%
- Veröffentlicht 26.06.2026 14:52:23
- Zuletzt bearbeitet 26.06.2026 18:17:00
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
CVE-2026-3001
- EPSS 0.38%
- Veröffentlicht 27.05.2026 07:45:54
- Zuletzt bearbeitet 27.05.2026 14:50:47
The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. Specifically, the `render_content()` met...
CVE-2026-2948
- EPSS 0.15%
- Veröffentlicht 05.05.2026 03:37:37
- Zuletzt bearbeitet 05.05.2026 19:08:20
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.5.3 via the import_images() function. This makes it possible for authenticated att...
CVE-2026-2868
- EPSS 0.15%
- Veröffentlicht 05.05.2026 02:26:57
- Zuletzt bearbeitet 05.05.2026 19:09:32
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'separatorIconSVG' parameter in versions up to, and including, 3.5.3 due to insufficient input sanitization an...
CVE-2026-2924
- EPSS 0.2%
- Veröffentlicht 04.04.2026 02:26:20
- Zuletzt bearbeitet 24.07.2026 22:10:00
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageLoad' parameter in versions up to, and including, 3.4.6 due to insufficient input sanitization and outpu...
CVE-2025-14984
- EPSS 0.28%
- Veröffentlicht 08.01.2026 09:20:52
- Zuletzt bearbeitet 07.10.2026 09:10:00
The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.3.2. This is due to the plugin's framework component adding SVG to the allowed MIME types via the upload...