CVE-2026-12399: Gutenverse <= 3.8.0 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fonts[].font.font.value' Parameter
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfilteredhtml has been disabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Gutenverse (WordPress Blocks, Page Builder & Site Editor plugin)to a version that resolves this vulnerability.Fixed in 3.8.0 - Configuration
If possible, re-enable unfiltered_html (the issue only affects installations where unfiltered_html has been disabled in combination with the stated multi-site conditions).
WordPress unfiltered_html = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12399?
CVE-2026-12399 has a medium severity score of 4.4.
How does CVE-2026-12399 affect Gutenverse plugin?
CVE-2026-12399 allows for authenticated (Editor+) users to execute stored Cross-Site Scripting attacks due to insufficient input sanitization.
What versions of Gutenverse are affected by CVE-2026-12399?
CVE-2026-12399 affects all versions of the Gutenverse plugin up to and including 3.8.0.
How can I mitigate the risks associated with CVE-2026-12399?
To mitigate CVE-2026-12399, update the Gutenverse plugin to the latest version that has addressed the vulnerability.
What type of attack is related to CVE-2026-12399?
CVE-2026-12399 is related to Stored Cross-Site Scripting (XSS) attacks.