CVE-2026-85677
Received Received - Intake

Gutenverse News WordPress Plugin XSS Vulnerability

Vulnerability report for CVE-2026-85677, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: WPScan

Description

The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in the browser of any administrator who reviews the comment queue, and of any visitor to the post once the comment is approved.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
artus_kg gutenverse_news to 3.3.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated stored Cross-Site Scripting (XSS) vulnerability in the Gutenverse News WordPress plugin before version 3.3.3. The plugin does not properly restrict HTML elements in comments, allowing unauthenticated users to inject malicious JavaScript that executes when an administrator reviews comments or when visitors view approved comments.

Detection Guidance

Check if the Gutenverse News WordPress plugin version is below 3.3.3. Inspect comment content for unusual JavaScript or HTML tags that may indicate stored XSS attempts. Review browser console logs for unexpected script executions when viewing comments.

Impact Analysis

Unauthenticated attackers can inject JavaScript into comment fields. This script executes when administrators review comments or when visitors view approved comments, potentially stealing session cookies, redirecting users to malicious sites, or performing actions on behalf of users without their consent.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's data protection principles and HIPAA's security requirements. It may result in data breaches, unauthorized disclosure of personal data, and non-compliance with regulatory obligations.

Mitigation Strategies

Update the Gutenverse News plugin to version 3.3.3 or later immediately. Temporarily disable comment functionality if an update is not immediately available. Monitor comment queues for suspicious content and remove any untrusted comments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85677. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart