Impact
The Gutenify – Visual Site Builder Blocks & Site Templates plugin is vulnerable to stored cross‑site scripting due to insufficient sanitization and escaping of user‑supplied block attributes. Contributed users or higher can inject arbitrary JavaScript into a block, which will then run in the browsers of any visitor who loads the affected page. The impact is the execution of malicious scripts with the same privileges as the visitor, potentially leading to credential theft, defacement, or other client‑side attacks. This weakness is represented by CWE-79. Based on the description, it is inferred that the malicious scripts could lead to credential theft, defacement, or other client‑side impacts.
Affected Systems
All versions of the Gutenify Visual Site Builder Blocks & Site Templates plugin released by codeyatri up to and including version 1.5.9 are affected. Sites that have installed any of these vulnerable releases are at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity vulnerability, while the EPSS score of less than 1% suggests low likelihood of exploitation in the wild. Since the vulnerability requires authenticated access with contributor-level or higher permissions, an attacker must first obtain or compromise such credentials before exploiting the flaw. The vulnerability is not listed in the CISA KEV catalog, but its nature allows for the injection of arbitrary scripts that can affect all users who view the edited content.
OpenCVE Enrichment