Executive brief
The Gutenverse plugin for WordPress, which provides design blocks for website building, contains a security flaw that allows users with contributor-level access to inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page. This could lead to unauthorized actions being performed on behalf of site administrators or the theft of sensitive session information.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Gutenverse WordPress plugin due to improper neutralization of the 'imageLoad' parameter. Authenticated attackers with contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into pages. Because the plugin fails to sufficiently sanitize input and escape output, these scripts are stored on the server and executed in the context of any user's browser session when they visit the compromised page. The vulnerability is addressed in versions following 3.4.6, as indicated by the available changeset.
Affected products
- jegstudio Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.4.6
Timeline
- 2026-04-04: disclosed
- 2026-04-04: advisory