Impact
The vulnerability is a DOM‑based XSS in the Gutentor WordPress plugin that fails to neutralize user input before rendering it in the browser. An attacker can craft malicious input that is interpreted as code, allowing injection of scripts that could steal credentials, deface content, or redirect users. This weakness is catalogued as CWE‑79.
Affected Systems
WordPress sites that use the Gutentor plugin version 3.4.3 or earlier are affected; any installation running 3.4.3 or below remains at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of < 1 % suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is client‑side, where a malicious user injects content that is later rendered in a visitor’s browser. No authentication or privileged access is required beyond the ability to create or update content, so all site visitors who view affected pages are at risk.
OpenCVE Enrichment
EUVD