CyberRota Analysis
AI-GeneratedThe GutenKit WordPress plugin prior to version 2.5.0 is vulnerable due to inadequate sanitization of uploaded SVG files, enabling users with file upload permissions to introduce malicious SVGs. This flaw can lead to Stored Cross-Site Scripting (XSS) attacks, potentially affecting all users, including administrators, who view the compromised content. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file upload capability, such as Author, to upload a malicious SVG and perform Stored Cross-Site Scripting attacks against any user opening it, including administrators.