Impact
Improper neutralization of input during web page generation leads to a stored cross‑site scripting flaw in the Gutenberg plugin. The vulnerability allows attackers to inject arbitrary script that executes in the browsers of users who view the affected content, potentially compromising user credentials, session tokens, or leading to defacement.
Affected Systems
Affecting the Gutenberg WordPress plugin developed by Matias Ventura, all releases up to and including version 21.8.2 are vulnerable. Sites that rely on this plugin for content editing are at risk if they have not applied a newer version.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalogue. The most likely attack vector involves an authenticated user submitting malicious content through the Gutenberg editor or similar content creation interfaces, which is then stored and rendered to other visitors.
OpenCVE Enrichment