Impact
The Gutenverse plugin contains a stored cross‑site scripting flaw that allows an authenticated user with contributor or higher privileges to insert malicious JavaScript into the 'suffixMain' attribute of the Post Comment block. The injected script is saved as a Gutenberg block delimiter comment and is later rendered as executable HTML, bypassing WordPress core sanitization. This enables the attacker to cause unintended script execution in the browsers of any visitor who views the affected page.
Affected Systems
The vulnerability affects the WordPress plugin Gutenverse – WordPress Blocks, Page Builder & Site Editor through version 4.0.8, including all releases up to and including 4.0.8. Users running any of these versions are susceptible; updates beyond 4.0.8 are not affected.
Risk and Exploitability
The flaw is scored 6.4 on CVSS, indicating moderate severity. The EPSS metric is not available, so the exploitation likelihood is undetermined. The issue is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user with contributor-level access or higher, as the attacker must submit a comment via the post comment block to store the payload. An attacker with such permissions could inject malicious scripts that would execute when any visitor laden the page, potentially compromising user credentials or performing other malicious actions.
OpenCVE Enrichment