Description
The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into pages served to other users and to anonymous visitors. JavaScript execution is not possible at that role, so the impact is limited to defacement, interface redressing and forcing external resources to load.
Published: 2026-09-02
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows users with the Contributor role or higher to store and load arbitrary CSS in the GutenKit plugin’s front‑end styling. The plugin does not validate or escape style settings before rendering them, enabling persistent defacement, UI redressing, or the loading of external resources. This weakness does not provide JavaScript execution or privilege escalation; it is limited to cosmetic manipulation of the page.

Affected Systems

WordPress sites running GutenKit version 2.5.0 or earlier. Any site where a Contributor or higher user can configure the plugin’s style settings is susceptible. The flaw is confined to the style‑setting functionality of the GutenKit plugin.

Risk and Exploitability

The CVSS base score is 3.5, reflecting low overall severity. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, indicating limited known exploitation. An attacker must be authenticated as a Contributor or higher, so the risk is moderate but not critical. Defacement or interface manipulation is the primary impact, with no possibility of payload delivery or data exfiltration.

Generated by OpenCVE AI on September 3, 2026 at 11:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update GutenKit to version 2.5.1 or later, which removes the CSS injection flaw
  • Restrict or revoke Contributor role privileges on compromised or unneeded accounts until the patch is applied
  • If an upgrade cannot be performed immediately, disable the GutenKit plugin or remove its style‑setting feature to block the vulnerability

Generated by OpenCVE AI on September 3, 2026 at 11:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into pages served to other users and to anonymous visitors. JavaScript execution is not possible at that role, so the impact is limited to defacement, interface redressing and forcing external resources to load.
Title GutenKit < 2.5.1 - Contributor+ Stored CSS Injection
Weaknesses CWE-74
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-02T14:57:38.255Z

Reserved: 2026-08-13T07:59:56.537Z

Link: CVE-2026-19698

cve-icon Vulnrichment

Updated: 2026-09-02T14:44:23.389Z

cve-icon NVD

Status : Deferred

Published: 2026-09-02T15:17:37.990

Modified: 2026-09-03T17:50:37.690

Link: CVE-2026-19698

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T12:00:04Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')