Impact
The GutenKit plugin for WordPress contains an improper neutralization of input during web page generation, which allows a stored cross‑site scripting flaw. Exploiting this can cause a web page to deliver malicious JavaScript, enabling session hijacking, data theft, or page defacement. The vulnerability aligns with CWE‑79, an input validation weakness that permits injection of executable code.
Affected Systems
Ataur R’s GutenKit gutenkit‑blocks‑addon WordPress plugin is affected in all versions from the first release through version 2.4.2. Any web site using this plugin installation is vulnerable until a newer version is deployed or the plugin is removed.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is less than 1 %, suggesting current exploitation activity is low, and the flaw is not listed in the CISA KEV catalog. However, a stored XSS can be triggered by injecting content through any input field or block editor that accepts user input, making the attack vector likely local through an authenticated WordPress user or, if the plugin allows unfiltered input, global. The risk increases if the site hosts sensitive data or relies on the plugin’s content for public pages.
OpenCVE Enrichment
EUVD