Junglewise Threat Intelligence

CVE-2026-19943: Gutenverse WordPress Blocks stored cross-site scripting in titleTag

CVE-2026-19943 · Severity: medium · CVSS 6.4 · Published 2026-08-25

Executive brief

Gutenverse is a popular WordPress page builder plugin used to create website pages and layouts. A vulnerability in the plugin allows authenticated users with contributor-level access to inject malicious scripts that execute when pages are viewed, potentially compromising site visitors' sessions and data. The injected code persists in the page and executes even during administrator preview sessions, affecting site security and visitor trust.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in the 'titleTag' block attribute of the Gutenverse plugin, affecting all versions up to and including 4.0.2. The root cause is insufficient input sanitization and output escaping; malicious payloads bypass wp_kses_post sanitization because they are embedded inside block-comment delimiters and only rendered at runtime via do_blocks(). An authenticated attacker with contributor-level access or higher can inject arbitrary JavaScript that persists in the page and executes in all user sessions, including administrator and editor previews. The vulnerability requires authentication and contributor-level privileges, but once injected, the payload is persistent and affects all visitors.

Affected products

  • gutenverse Gutenverse – WordPress Blocks, Page Builder & Site Editor up to and including 4.0.2

Timeline

  • 2026-08-25: disclosed

References