Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons
Gutenverse News adds Gutenberg blocks for creating news, magazine, blog, and editorial content layouts.
Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons (gutenverse-news) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 8.8.
gutenverse-newsCVE-2026-85677: Gutenverse News turns unauthenticated comments into stored XSS
Gutenverse News before 3.3.3 adds extra allowed HTML globally instead of limiting it to the intended sanitization context. An unauthenticated commenter can therefore store JavaScript that executes when an administrator reviews the comment queue and, after approval, when visitors view the post. The authoritative export does not identify the filter, HTML element, or attribute involved.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-85677
Gutenverse News turns unauthenticated comments into stored XSS
Gutenverse News before 3.3.3 adds extra allowed HTML globally instead of limiting it to the intended sanitization context. An unauthenticated commenter can therefore store JavaScript that executes when an administrator reviews the comment queue and, after approval, when visitors view the post. The authoritative export does not identify the filter, HTML element, or attribute involved.
|
3.3.3 |
CVE8.8
NVDPending
|
| Dec 09, 2025 |
CVE-2025-62090
Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons: A security weakness
Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jun 19, 2025 |
CVE-2025-5234
Gutenverse News: Cross-site scripting
Gutenverse News is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|