Extension WordPress
Vulnérabilités Gutenverse – WordPress Blocks, Page Builder & Site Editor
Cette page rassemble les failles publiées pour Gutenverse – WordPress Blocks, Page Builder & Site Editor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Gutenverse – WordPress Blocks, Page Builder & Site Editor
12 fiches
Gutenverse <= 3.8.0 – Authenticated (Editor+) Stored Cross-Site Scripting via 'fonts[].font.font.value' Parameter
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping.…
*-3.8.0
3.8.1
26/06/2026
Gutenverse <= 3.4.6 – Reflected Cross-Site Scripting via 's' Parameter
The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. Specifically, the `render_content()` method in `class-search-result-title.php` outputs…
*-3.4.6
3.4.7
26/05/2026
Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 – Authenticated (Contributor+) Server-Side Request Forgery via 'imageUrl'
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.5.3 via the import_images() function. This makes it possible for authenticated attackers, with…
*-3.5.3
3.6.0
04/05/2026
Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'separatorIconSVG'
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'separatorIconSVG' parameter in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping.…
*-3.5.3
3.6.0
04/05/2026
Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.4.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'imageLoad'
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageLoad' parameter in versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping.…
*-3.4.6
3.4.7
03/04/2026
Gutenverse <= 3.2.1 – Missing Authorization
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.1. This makes it…
*-3.2.1
3.3.0
28/11/2025
Gutenverse <= 3.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Fun Fact Blocks
The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Fun Fact blocks in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping on user…
*-3.1.0
3.1.1
05/08/2025
Gutenverse <= 2.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via countdown Block
The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's countdown Block in all versions up to, and including, 2.2.1 due to insufficient input…
*-2.2.1
3.0.0
28/04/2025
Gutenverse <= 1.9.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-1.9.4
2.0.0
26/08/2024
Gutenverse <= 1.9.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-1.9.2
1.9.3
19/07/2024
Gutenverse <= 1.9.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Gutenverse – Gutenberg Blocks – Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 1.9.0 due to insufficient input sanitization…
*-1.9.0
1.9.1
12/04/2024
Gutenverse <= 1.8.5 – Missing Authorization via 'data/update' API Endpoint
The Gutenverse plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'data/update' API Endpoint function in versions up to, and including, 1.8.5. This makes it possible for unauthenticated attackers…
*-1.8.5
1.8.6
19/06/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.