Executive brief
Gutenverse Form is a WordPress plugin used to create and manage forms on websites. A security vulnerability in versions 2.4.7 and earlier allows unauthenticated attackers to inject malicious scripts into the site. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could steal session information, redirect users to malicious websites, or perform unauthorized actions on the site.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Gutenverse Form plugin for WordPress in versions up to and including 2.4.7. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into visiting a crafted URL or submitting a malicious form. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized administrative actions if the victim is a site administrator. The issue is resolved in version 2.5.0.
Affected products
- Gutenverse Gutenverse Form <= 2.4.7
Timeline
- 2026-02-19: other: Reported by hivesec
- 2026-06-24: advisory: Patchstack advisory published
- 2026-06-26: disclosed: NVD publication date
- 2026-06-26: patched: Patch available in version 2.5.0