Executive brief
The Gutenverse Companion plugin for WordPress, which provides additional blocks and features for site building, contains a security flaw that allows unauthorized users to perform actions they should not have access to. An attacker could exploit this to modify site settings or content without needing to log in. This could lead to unauthorized changes to the website's appearance or functionality, potentially impacting the site's integrity and reputation.
Technical details
The Gutenverse Companion plugin for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in versions up to and including 2.5.0. This vulnerability allows a remote, unauthenticated attacker to execute functions or actions that should be restricted to higher-privileged users. The flaw stems from a lack of proper validation of user permissions or security nonces. An attacker can exploit this over the network without any user interaction to modify site configurations or data. The issue is resolved in version 2.5.1.
Affected products
- Jegstudio Gutenverse Companion <= 2.5.0
Timeline
- 2026-06-05: other: Reported by researcher mxym
- 2026-06-17: advisory: Patchstack advisory published
- 2026-06-26: disclosed: CVE published to NVD
- 2026-06-26: patched: Patch available in version 2.5.1