CVE-2026-19943: Gutenverse <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' Block Attribute

Published Aug 25, 2026
·
Updated

The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'titleTag' Block Attribute in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The malicious titleTag value survives wpksespost on save because it is stored inside a block-comment delimiter and the live HTML is only synthesized at render time by doblocks(), meaning the payload also fires in administrator and editor sessions during post preview.

Affected Software

1 affected component
Gutenverse Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress<=4.0.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress to a version that resolves this vulnerability.

    Fixed in 4.0.2
  2. Compensating control

    Because the vulnerability can fire during post preview/render for admin/editor sessions, restrict editor access (preview/render) to trusted users only; limit contributor-level permissions so untrusted contributors cannot create or modify Gutenverse block content containing 'titleTag' attributes.

Event History

Aug 25, 2026
CVE Published
via MITRE·03:27 AM
Data Sourced
via MITRE·03:27 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which users can exploit this issue?

An attacker needs an authenticated WordPress account with Contributor-level access or higher. They can place a malicious titleTag block attribute into a page.

2

Who is at risk when a malicious page is viewed?

The injected script executes for users who access the affected page. Administrator and editor sessions are also exposed when previewing the malicious post.

3

Are installations running Gutenverse 4.0.2 affected?

Yes. The issue affects all Gutenverse versions up to and including 4.0.2.

4

How does the payload persist despite WordPress sanitization?

The malicious titleTag value is stored inside a block-comment delimiter, allowing it to survive wp_kses_post during saving. The live HTML is generated later when do_blocks() renders the page.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203