Impact
The Gutenverse plugin fails to sanitize user input and escape output in several block types, allowing an authenticated user with Contributor level or higher to inject malicious scripts that run whenever a visitor views the affected page. This form of cross‑site scripting can be used to hijack sessions, deface content, or deliver malware to site users. The flaw is a classic CWE‑79 input validation error.
Affected Systems
The vulnerability is present in the Gutenbergverse – WordPress Blocks, Page Builder & Site Editor plugin developed by jegstudio, in all releases up to and including version 4.0.2. Any WordPress site that has installed this plugin without upgrading to a newer version is affected.
Risk and Exploitability
The CVSS base score of 6.4 indicates moderate severity. The exploit requires that the attacker be authenticated with at least Contributor privileges and that affected pages are viewed by a victim. Although the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the nature of the attack—remote script execution in the user’s browser—poses a serious threat to confidentiality, integrity, and availability of site content. The attack vector is likely to be accomplished over the web by exploiting the editable blocks within the WordPress editor.
OpenCVE Enrichment