Plugin Vulnerability Hub
Plugin 8 known issues Latest disclosed Apr 22, 2026

Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Vulnerabilities

Review known vulnerability records for the WordPress plugin Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor (`gutentor`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-2951, CVE-2025-58680 and CVE-2025-58783, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
8
High or Critical
0
Patch Coverage
100%
Last Updated
Apr 22, 2026
Priority CVE Quick Links

Fast paths into Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
8
CVE-2025-4685 Medium 3.4.9
CVE-2025-4685 Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Stored Cross-Site Scripting

Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

CVE-2025-22293 Medium 3.4.4
CVE-2025-22293 Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Stored Cross-Site Scripting

Gutentor <= 3.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2024-10178 Medium 3.4.0
CVE-2024-10178 Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Stored Cross-Site Scripting

Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

CVE-2024-43308 Medium 3.3.6
CVE-2024-43308 Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Stored Cross-Site Scripting

Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2026-2951 Medium 3.5.6
CVE-2026-2951 Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Stored Cross-Site Scripting

Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML

CVE-2025-58680 Medium 3.5.3
CVE-2025-58680 Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Vulnerability

Gutentor <= 3.5.2 - Missing Authorization

CVE-2025-1986 Medium 3.4.7
CVE-2025-1986 Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor SQL Injection

Gutentor <= 3.4.6 - Authenticated (Administrator+) SQL Injection

CVE-2025-58783 Medium 3.5.6
CVE-2025-58783 Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Vulnerability

Gutentor <= 3.5.5 - Missing Authorization

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
8 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 0 high severity findings.
Recent CVEs
CVE-2026-2951, CVE-2025-58680 and CVE-2025-58783
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-2951
CVE-2026-2951: Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...

Published
Apr 22, 2026
Patched Release
3.5.6
Affected Versions
Versions up to 3.5.5
Next Step
Update to 3.5.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-58680
CVE-2025-58680: Gutentor <= 3.5.2 - Missing Authorization

The Gutentor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.5.2. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized...

Published
Sep 22, 2025
Patched Release
3.5.3
Affected Versions
Versions up to 3.5.2
Next Step
Update to 3.5.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-58783
CVE-2025-58783: Gutentor <= 3.5.5 - Missing Authorization

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.5. This makes it possible for authenticated attackers, with Cont...

Published
Sep 05, 2025
Patched Release
3.5.6
Affected Versions
Versions up to 3.5.5
Next Step
Update to 3.5.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-4685
CVE-2025-4685: Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML data attributes of multiple widgets, in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output es...

Published
Jul 20, 2025
Patched Release
3.4.9
Affected Versions
Versions up to 3.4.8
Next Step
Update to 3.4.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-1986
CVE-2025-1986: Gutentor <= 3.4.6 - Authenticated (Administrator+) SQL Injection

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL q...

Published
Mar 11, 2025
Patched Release
3.4.7
Affected Versions
Versions up to 3.4.6
Next Step
Update to 3.4.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-22293
CVE-2025-22293: Gutentor <= 3.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Gutentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to injec...

Published
Jan 06, 2025
Patched Release
3.4.4
Affected Versions
Versions up to 3.4.3
Next Step
Update to 3.4.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-10178
CVE-2024-10178: Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user s...

Published
Dec 04, 2024
Patched Release
3.4.0
Affected Versions
Versions up to 3.3.9
Next Step
Update to 3.4.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-43308
CVE-2024-43308: Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...

Published
Aug 16, 2024
Patched Release
3.3.6
Affected Versions
Versions up to 3.3.5
Next Step
Update to 3.3.6 or newer if supported.