Junglewise Threat Intelligence

CVE-2026-3001: Gutenverse WordPress plugin reflected XSS in search-result-title

CVE-2026-3001 · Severity: medium · CVSS 6.1 · Published 2026-05-27

Executive brief

The Gutenverse plugin for WordPress, which provides advanced blocks for site building, is vulnerable to a security flaw that allows attackers to run malicious scripts in a user's browser. This occurs when a user clicks a specially crafted link that targets the site's search functionality. If successful, an attacker could potentially steal user session information or perform unauthorized actions on behalf of the victim.

Technical details

The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to improper neutralization of the 's' (search) query parameter. Specifically, the render_content() method in class-search-result-title.php retrieves the search query using get_query_var('s') and outputs it directly into the HTML without applying escaping functions like esc_html(). An unauthenticated attacker can exploit this by tricking a user into clicking a crafted URL. This vulnerability requires the 'gutenverse/search-result-title' block to be active on the site's search results template. A patch has been released in version 3.4.7 (implied by the changeset reference).

Affected products

  • Gutenverse Gutenverse up to, and including, 3.4.6

Timeline

  • 2026-05-27: advisory: Published by Wordfence and NVD

References