Impact
The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress contains a stored cross‑site scripting vulnerability that allows authenticated users with Contributor permissions or higher to inject arbitrary JavaScript into the postBodyCss field. The injected script is stored in the page content and will run whenever a visitor loads the affected page, potentially enabling cookie theft, session hijacking, or other malicious client‑side activities. The weakness resides in inadequate input sanitization and missing output escaping, classified as CWE‑79.
Affected Systems
All versions of GutenKit up to and including 2.4.4 are impacted. The vulnerability is specific to the WordPress plugin and affects sites that shop the Gutenberg Block Editor, regardless of the underlying WordPress version.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity attack. The exploit requires authenticated access at the Contributor level or higher, which limits the exposure to users who can edit or create pages. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalog, suggesting no documented exploit activity so far. Nonetheless, the nature of the flaw permits arbitrary code execution on the client side, warranting prompt remediation.
OpenCVE Enrichment