S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-3001 Scanner

CVE-2026-3001 Scanner - Cross-Site Scripting vulnerability in Gutenverse Plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-3001
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. Specifically, the `render_content()` method in `class-search-result-title.php` outputs the value of `get_query_var('s')` directly into the page HTML without applying `esc_html()` or any other escaping function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages via a crafted URL that execute if a user clicks the link, provided the `gutenverse/search-result-title` block is present on the site's search results template.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Gutenverse – WordPress Blocks, Page Builder & Site Editorby jegstudio
0
Updated Aug 22, 2026View on NVD →
Detail

The Gutenverse Plugin for WordPress, designed for creating and customizing block-based WordPress sites, is utilized by individuals and organizations seeking flexible website content management and design capabilities. Developed by Jegstudio, this plugin serves a broad spectrum of users ranging from bloggers to web developers, enabling the integration of dynamic block elements into websites. With a user-friendly interface and extensive customization options, Gutenverse facilitates the building of visually appealing websites while ensuring an efficient workflow in Wordpress site development. Notably, its features cater to both non-technical users and developers seeking enhanced control over site presentation and functionality. Intended to enhance the WordPress user experience, Gutenverse is a vital tool for those aiming to fully exploit WordPress's potential in intuitive site design.

The vulnerability addressed in this scanner is a Reflected Cross-Site Scripting (XSS) vulnerability identified in the Gutenverse Plugin for WordPress. This particular security issue allows unauthenticated attackers to inject and execute arbitrary web scripts through the 's' parameter in specific plugin versions. Insufficient input sanitization and output escaping within the 'render_content()' method in certain plugin files contribute to this exposure. Particularly, this vulnerability stems from improperly handling user input within URL parameters, resulting in potential malicious script execution. Such vulnerabilities can be critical as they enable attackers to perform phishing attacks or other malicious activities against unsuspecting site visitors.

The vulnerability resides in the 'render_content()' method of the 'class-search-result-title.php' file within the Gutenverse Plugin, specifically affecting how the site handles query variables. The affected parameter, 'get_query_var('s')', lacks adequate sanitization and escaping, allowing harmful scripts to be injected directly into a site's HTML. When the 'gutenverse/search-result-title' block is present on a WordPress site, crafted URLs can exploit this flaw to render scripts in users' browsers. Attackers can thereby execute harmful web scripts, exploiting the site's search template to bypass typical user interaction constraints, typically a reflection XSS vulnerability's hallmark.

Exploiting this vulnerability allows malicious actors to execute arbitrary scripts within the browsers of users who visit affected sites. Potentially severe consequences include unauthorized session hijacking, facilitating identity theft by gaining session cookies, or executing further attacks. Additionally, users can be redirected to fraudulent websites through phishing schemes, leading to significant data breaches. Overall, such exploitation compromises user security and undermines trustworthiness associated with the affected websites.

REFERENCES

Solution Advice
  • Update the Gutenverse Plugin to a version later than 3.4.6 or the latest available version to patch the vulnerability.
  • Implement a web application firewall (WAF) to help filter and monitor HTTP requests for malicious content.
  • Use plugins or services that sanitize input and escape output to prevent XSS vulnerabilities.
  • Regularly review and audit plugin security settings and user permissions.
  • Educate users and administrators on the risks of XSS and best practices to avoid exploitation.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.