Impact
The vulnerability allows users with the Contributor role or higher to store and load arbitrary CSS in the GutenKit plugin’s front‑end styling. The plugin does not validate or escape style settings before rendering them, enabling persistent defacement, UI redressing, or the loading of external resources. This weakness does not provide JavaScript execution or privilege escalation; it is limited to cosmetic manipulation of the page.
Affected Systems
WordPress sites running GutenKit version 2.5.0 or earlier. Any site where a Contributor or higher user can configure the plugin’s style settings is susceptible. The flaw is confined to the style‑setting functionality of the GutenKit plugin.
Risk and Exploitability
The CVSS base score is 3.5, reflecting low overall severity. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, indicating limited known exploitation. An attacker must be authenticated as a Contributor or higher, so the risk is moderate but not critical. Defacement or interface manipulation is the primary impact, with no possibility of payload delivery or data exfiltration.
OpenCVE Enrichment