CVE detail
CVE-2026-12399
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
13 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 22, 2026 to June 28, 2026)Wordfence
SMTP HD Quiz 2.2.0 - 2.2.1 - Cross-Site Request Forgery via Multiple AJAX Handlers 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-13422 Patch Status Patched Published Jun 26, 2026 Affected Software HD Quiz [hd-quiz] Researcher Wordfence PRISM More Details > Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator Majestic Support – The
vendorwww.wordfence.comJul 2, 2026, 6:34 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/fd1c679b-43e0-4e3a-ae2d-f6ff8a657512?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJun 27, 2026, 8:16 AM - https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3578328%40gutenverse&new=3578328%40gutenverse&sfp_email=&sfph_mail=plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/gutenverse/tags/3.8.0/lib/framework/includes/class-global-variable.php#L78plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/gutenverse/tags/3.8.0/lib/framework/includes/class-frontend-generator.php#L147plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/gutenverse/tags/3.8.0/lib/framework/includes/class-api.php#L1956plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/gutenverse/tags/3.8.0/lib/framework/helper.php#L1775plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/gutenverse/tags/3.8.0/lib/framework/helper.php#L1440plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/gutenverse/tags/3.6.3/lib/framework/includes/class-global-variable.php#L78plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/gutenverse/tags/3.6.3/lib/framework/includes/class-frontend-generator.php#L147plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/gutenverse/tags/3.6.3/lib/framework/includes/class-api.php#L1956plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/gutenverse/tags/3.6.3/lib/framework/helper.php#L1775plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/gutenverse/tags/3.6.3/lib/framework/helper.php#L1440plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 8:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-14856CVSS 6.3 · Medium
A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization…
- CVE-2026-65764CVSS 5.1 · Medium
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.
- CVE-2026-15928CVSS 8.2 · High
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.
- CVE-2026-17496CVSS 8.1 · High
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without…
- CVE-2026-15425CVSS 6.4 · Medium
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up…
- CVE-2026-57531CVSS 5.1 · Medium
Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScrip…