WordPress Plugin Vulnerabilities

GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload

Description

The plugin does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file upload capability, such as Author, to upload a malicious SVG and perform Stored Cross-Site Scripting attacks against any user opening it, including administrators.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Yaswanth Reddy Sunkara
Submitter
Yaswanth Reddy Sunkara
Verified
Yes

Timeline

Publicly Published
2026-08-18 (about 3 days ago)
Added
2026-08-18 (about 2 days ago)
Last Updated
2026-08-18 (about 2 days ago)

Other