Executive brief
Gutenverse is a popular WordPress plugin that provides page-building blocks for creating custom website layouts. The plugin fails to properly sanitize user input in multiple blocks, allowing website editors (Contributor-level users and above) to inject malicious scripts that execute for all site visitors. An attacker with editor access could deface pages, steal visitor data, or redirect users to malicious sites.
Technical details
The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in multiple Gutenverse blocks caused by insufficient input sanitization and output escaping. Authenticated attackers with Contributor-level access or above can inject arbitrary JavaScript payloads into page content via block parameters. The stored payload executes in the context of any user viewing the affected page, including administrators. This requires attacker authentication but no user interaction beyond visiting the compromised page. Patches are available in versions after 4.0.2.
Affected products
- Gutenverse Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem up to and including 4.0.2
Timeline
- 2026-08-26: disclosed