Vulnerability Brief
CVE-2026-12399
What this means for your business
A security vulnerability has been discovered in the WordPress plugin called Gutenverse, which is used to create and edit pages on your website. This vulnerability allows an attacker with editor-level access to inject malicious code into your website's pages, which can be executed when other users visit those pages. If left unpatched, this vulnerability could potentially allow an attacker to compromise your website's security and access sensitive information.
- Severity: MEDIUM
- CVSS score: 4.4
Technical summary
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.