CVE-2025-49032: WordPress Gutenberg Blocks plugin <= 3.3.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Gutenberg Blocks advanced-gutenberg allows Stored XSS.This issue affects Gutenberg Blocks: from n/a through <= 3.3.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Gutenberg Blocks allows Stored XSS.This issue affects Gutenberg Blocks: from n/a through 3.3.1.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49032?
CVE-2025-49032 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-49032?
To fix CVE-2025-49032, update the PublishPress Gutenberg Blocks plugin to version 3.3.2 or later.
Who is affected by CVE-2025-49032?
CVE-2025-49032 affects users of PublishPress Gutenberg Blocks versions up to and including 3.3.1.
What type of vulnerability is CVE-2025-49032?
CVE-2025-49032 is an improper neutralization of input during web page generation, leading to a stored cross-site scripting (XSS) vulnerability.
Can CVE-2025-49032 lead to data breaches?
Yes, CVE-2025-49032 can potentially lead to data breaches by allowing attackers to execute malicious scripts in the context of a user's browser.