Junglewise Threat Intelligence

CVE-2026-3002: Gutenverse Ultimate WordPress FSE Blocks stored cross-site scripting

CVE-2026-3002 · Severity: medium · CVSS 6.4 · Published 2026-08-26

Executive brief

Gutenverse is a popular WordPress plugin that provides page-building blocks for creating custom website layouts. The plugin fails to properly sanitize user input in multiple blocks, allowing website editors (Contributor-level users and above) to inject malicious scripts that execute for all site visitors. An attacker with editor access could deface pages, steal visitor data, or redirect users to malicious sites.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in multiple Gutenverse blocks caused by insufficient input sanitization and output escaping. Authenticated attackers with Contributor-level access or above can inject arbitrary JavaScript payloads into page content via block parameters. The stored payload executes in the context of any user viewing the affected page, including administrators. This requires attacker authentication but no user interaction beyond visiting the compromised page. Patches are available in versions after 4.0.2.

Affected products

  • Gutenverse Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem up to and including 4.0.2

Timeline

  • 2026-08-26: disclosed

References