Impact
The vulnerability is an improper neutralization of input that permits stored cross‑site scripting in the Gutena Kit plugin. Exploitation would allow an attacker to inject arbitrary JavaScript into pages viewed by other users, potentially stealing session cookies, defacing content, or redirecting users to malicious sites. This weakness is identified as CWE‑79 and provides client‑side code execution without needing elevated privileges on the server.
Affected Systems
Affected is the WordPress plugin Gutena Kit – Gutenberg Blocks and Templates by Saad Iqbal. All releases through version 2.0.7 are vulnerable; newer releases are presumed fixed. The issue appears when the plugin accepts user‑supplied content that is not sanitised and stores it for display.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would likely target sites that allow content creation through Gutena Kit or grant administrators permission to input data. The stored nature of the flaw means that a single injection can affect all visitors until the content is removed or sanitized.
OpenCVE Enrichment
EUVD