SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-19697

MEDIUM · CVSS 6.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The GutenKit WordPress plugin prior to version 2.5.0 is vulnerable due to inadequate sanitization of uploaded SVG files, enabling users with file upload permissions to introduce malicious SVGs. This flaw can lead to Stored Cross-Site Scripting (XSS) attacks, potentially affecting all users, including administrators, who view the compromised content. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-19697
Severity
MEDIUM
CVSS
6.8
EPSS
0.29%
WordPress

Original NVD Description

The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file upload capability, such as Author, to upload a malicious SVG and perform Stored Cross-Site Scripting attacks against any user opening it, including administrators.