The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00032}

epss

{'score': 0.00036}


Wed, 09 Jul 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Gutentor
Gutentor gutentor
CPEs cpe:2.3:a:gutentor:gutentor:*:*:*:*:*:wordpress:*:*
Vendors & Products Gutentor
Gutentor gutentor

Thu, 05 Dec 2024 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Dec 2024 04:45:00 +0000

Type Values Removed Values Added
Description The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-12-05T04:23:53.349Z

Updated: 2024-12-05T11:13:25.292Z

Reserved: 2024-10-18T21:47:17.751Z

Link: CVE-2024-10178

cve-icon Vulnrichment

Updated: 2024-12-05T11:05:53.770Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-05T05:15:06.613

Modified: 2025-07-09T13:01:14.860

Link: CVE-2024-10178

cve-icon Redhat

No data.