The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. Specifically, the `render_content()` method in `class-search-result-title.php` outputs the value of `get_query_var('s')` directly into the page HTML without applying `esc_html()` or any other escaping function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages via a crafted URL that execute if a user clicks the link, provided the `gutenverse/search-result-title` block is present on the site's search results template.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jegstudio
Jegstudio gutenverse – Wordpress Blocks, Page Builder & Site Editor Wordpress Wordpress wordpress |
|
| Vendors & Products |
Jegstudio
Jegstudio gutenverse – Wordpress Blocks, Page Builder & Site Editor Wordpress Wordpress wordpress |
Wed, 27 May 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. Specifically, the `render_content()` method in `class-search-result-title.php` outputs the value of `get_query_var('s')` directly into the page HTML without applying `esc_html()` or any other escaping function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages via a crafted URL that execute if a user clicks the link, provided the `gutenverse/search-result-title` block is present on the site's search results template. | |
| Title | Gutenverse <= 3.4.6 - Reflected Cross-Site Scripting via 's' Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-27T07:45:54.896Z
Reserved: 2026-02-23T03:07:28.125Z
Link: CVE-2026-3001
No data.
Status : Received
Published: 2026-05-27T08:16:40.440
Modified: 2026-05-27T08:16:40.440
Link: CVE-2026-3001
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:06:38Z
Weaknesses