CVE-2025-2893

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's countdown Block in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>Gutenverse is a WordPress blocks plugin, page builder, and website builder for the native Block Editor and Site Editor. Create fast, responsive websites without code using 57 blocks, 600+ templates, global styles, responsive controls, popup builder tools, and block theme support.</p> <p>Build landing pages, business websites, blogs, portfolios, headers, footers, archive templates, single post templates, popups, and full site designs with WordPress blocks in the native Block Editor and Site Editor.</p> <p>Use Gutenverse when you want a lightweight page builder experience that extends WordPress, Gutenberg, and the Site Editor instead of replacing the editor.</p> <h4>Why Choose Gutenverse</h4> <ul> <li>Build pages and websites with WordPress blocks</li> <li>Use page builder controls inside the native Block Editor</li> <li>Create full site layouts with the WordPress Site Editor</li> <li>Start from 600+ starter templates, sections, and layouts</li> <li>Use block themes and Full Site Editing (FSE)</li> <li>Design responsive pages for desktop, tablet, and mobile</li> <li>Build popups, landing pages, headers, footers, and post templates</li> <li>Keep the editing workflow close to WordPress core</li> </ul> <h4>Key Features</h4> <ul> <li>57 WordPress blocks for the Block Editor</li> <li>600+ ready-to-import starter templates and sections</li> <li>WordPress Site Editor and block theme support</li> <li>Page builder controls inside the native Block Editor</li> <li>Popup builder tools</li> <li>Responsive editing controls and custom breakpoints</li> <li>Global color and global font controls</li> <li>Flexible layout blocks for sections, containers, and columns</li> <li>Block management to enable or disable unused blocks</li> <li>Icon library with 100+ icons</li> <li>Advanced styling controls for spacing, background, border, typography, visibility, and animation</li> <li>Lightweight, performance-focused website building experience</li> </ul> <h4>WordPress Blocks Included</h4> <p>Gutenverse includes layout blocks, content blocks, design blocks, post blocks, and site building blocks for WordPress.</p> <p>Block categories include:</p> <ul> <li>Layout and wrapper blocks: Container, Section, Column, Flexible Wrapper, and Popup Builder</li> <li>Content and design blocks: Heading, Button, Image, Gallery, Tabs, Accordion, Icon Box, Team, Testimonials, Google Maps, and more</li> <li>Post and site blocks: Post Block, Post Title, Post Content, Post Featured Image, Archive Title, and Search Result Title</li> </ul> <p>Explore the full block list at <a href="https://gutenverse.com/blocks/" rel="nofollow ugc">Gutenverse Blocks</a>.</p> <h4>Template Library</h4> <p>Gutenverse includes 600+ starter templates, layouts, and sections for faster website creation. Start from prebuilt designs, then customize each section with WordPress blocks, responsive controls, global colors, and global fonts.</p> <p>Template types include landing pages, business websites, portfolio layouts, content sections, headers, footers, archive layouts, single post layouts, and full site templates.</p> <h4>Built For The WordPress Site Editor</h4> <p>Gutenverse works with the WordPress Site Editor, block themes, and Full Site Editing. You can create and customize site parts such as headers, footers, archive pages, and single post templates using WordPress blocks.</p> <p>For a ready-made block theme, try <a href="https://wordpress.org/themes/unibiz/" rel="ugc">Unibiz</a>.</p> <h4>Free And Pro Features</h4> <p>The free version of Gutenverse includes the core WordPress blocks, template library access, responsive controls, global styles, layout tools, and popup builder features needed to build a complete WordPress website.</p> <p>Gutenverse Pro adds advanced blocks, templates, form builder tools, popup options, dynamic data, display conditions, custom fonts, premium templates, and advanced site building features.</p> <h3>Use of 3rd-Party Services</h3> <p>Gutenverse may connect to the following third-party services when you enable or use related features.</p> <h4>Gutenverse.com</h4> <p>The Gutenverse dashboard may show optional links, template/library access, theme data, documentation, support, banners, license checks, or newsletter subscription features from gutenverse.com. Newsletter data is sent only when you manually submit your email address.</p> <p>Website: https://gutenverse.com/<br /> Terms: https://gutenverse.com/terms-and-conditions/</p> <h4>Google Maps</h4> <p>If you add the Google Maps block, the map may load content from Google Maps.</p> <p>Service endpoint: https://maps.google.com/maps<br /> Privacy Policy: https://policies.google.com/privacy<br /> Terms of Service: https://policies.google.com/terms</p> <h4>Google Fonts</h4> <p>Some Gutenverse dashboard screens may load Google Fonts for dashboard typography.</p> <p>Service endpoint: https://fonts.googleapis.com/<br /> Privacy Policy: https://policies.google.com/privacy<br /> Terms of Service: https://policies.google.com/terms</p> <h4>Social Share Links</h4> <p>If you use social sharing blocks, visitors may open external social sharing URLs when they click a share button.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
1.34M