Impact
A malicious SVG file can be uploaded by any WordPress user who has the ability to upload files, such as an author, because the GutenKit plugin does not sanitise the file across all upload paths. When another user, including an administrator, later views the uploaded file, the contained script payload is interpreted by the browser, allowing the attacker to execute arbitrary script in the context of that user’s browser session. The compromise is fully client‑side and does not require exploitation of server‑side code, but it can be used to deface content, exfiltrate cookies, or conduct phishing attacks against site users.
Affected Systems
WordPress sites that use the GutenKit plugin version prior to 2.5.0. The vulnerability exists in all upload paths enabled by the plugin and applies to every user who can upload files—typically users with the Author role—within those sites.
Risk and Exploitability
The vulnerability has a CVSS score of 6.8, indicating a medium severity. The EPSS score is less than 1 %, suggesting that real‑world exploitation is unlikely at present. It is not listed in CISA’s KEV catalog. The most likely attack vector is a user with file‑upload permissions, such as an Article author, uploading a crafted SVG that will later be rendered for other site users.
OpenCVE Enrichment