CVE-2025-46253: WordPress GutenKit plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit gutenkit-blocks-addon allows Stored XSS.This issue affects GutenKit: from n/a through <= 2.2.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46253?
CVE-2025-46253 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS), allowing attackers to execute malicious scripts.
How do I fix CVE-2025-46253?
To fix CVE-2025-46253, update the GutenKit plugin to version 2.2.3 or later, which addresses the XSS vulnerability.
What versions of GutenKit are affected by CVE-2025-46253?
CVE-2025-46253 affects GutenKit versions up to and including 2.2.2.
Can CVE-2025-46253 lead to data theft?
Yes, CVE-2025-46253 can potentially lead to data theft because attackers can exploit the stored XSS to access sensitive user information.
What types of attacks can CVE-2025-46253 enable?
CVE-2025-46253 can enable various attacks, including session hijacking, credential theft, and defacement of web pages through stored XSS exploits.