CVE-2025-22293: WordPress Gutentor plugin <= 3.4.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gutentor Gutentor gutentor allows DOM-Based XSS.This issue affects Gutentor: from n/a through <= 3.4.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22293?
CVE-2025-22293 is classified as a high severity vulnerability due to its exploitation potential for Cross-site Scripting (XSS).
How do I fix CVE-2025-22293?
To fix CVE-2025-22293, upgrade the Gutentor plugin to version 3.4.1 or later as it contains the necessary patches.
What software is affected by CVE-2025-22293?
CVE-2025-22293 affects Gutentor versions up to and including 3.4.0.
What type of vulnerability is CVE-2025-22293?
CVE-2025-22293 is a Cross-site Scripting (XSS) vulnerability that allows for the improper neutralization of input during web page generation.
Can CVE-2025-22293 lead to data theft?
Yes, if exploited, CVE-2025-22293 may allow attackers to steal sensitive user data through malicious scripts.