Description
The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in the browser of any administrator who reviews the comment queue, and of any visitor to the post once the comment is approved.
Published: 2026-09-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability the Gutenverse News WordPress plugin. Because the plugin applies a sanitisation contexts, unauthenticated users can embed JavaScript in comment content that will be executed when an administrator views the comment queue or when any visitor sees the approved post. This allows arbitrary script execution in the browser of those usersSS score is 8.8, and EPSS value is not available; the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw from any IP that can submit an unauthenticated comment, a capability normally available to anonymous visitors. The impact is limited to the browsers of administrators reviewing comments or visitors viewing approved content; the flaw remains until the malicious comments are removed or the plugin is updated.

Affected Systems

Any WordPress site that has the Gutenverse News plugin installed with a version earlier than 3.3.3 is affected. The vulnerability exists regardless of the WordPress core version.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. Because the flaw is triggered by submitting a malformed comment without authentication, the attack vector is local to the web application and does not require privileged access; any external user can exploit it. The lack of EPSS data and the absence from the CISA KEV catalog suggest that no widespread exploitation has been publicly reported yet, but the available evidence shows that an attacker could inject and execute arbitrary JavaScript in the browsers of site administrators reviewing the comment queue or of visitors viewing content after the comment is approved.

Generated by OpenCVE AI on September 11, 2026 at 14:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Gutenverse News plugin to version 3.3.3 or later, which restricts allowed tags to the intended context.
  • Disable comment posting for unauthenticated users or require users to register before commenting until a patch can be applied.
  • Remove is not feasible, and clear any stored comments that may contain injected JavaScript.

Generated by OpenCVE AI on September 11, 2026 at 14:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in the browser of any administrator who reviews the comment queue, and of any visitor to the post once the comment is approved.
Title Gutenverse News < 3.3.3 - Unauthenticated Stored XSS via Comment Content
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-11T10:09:19.338Z

Reserved: 2026-09-04T13:34:15.574Z

Link: CVE-2026-85677

cve-icon Vulnrichment

Updated: 2026-09-11T10:01:59.739Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T07:16:47.147

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-85677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T14:15:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')