CVE-2026-19697 PUBLISHED

GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload

Assigner: WPScan
Reserved: 13.08.2026 Published: 20.08.2026 Updated: 20.08.2026

The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file upload capability, such as Author, to upload a malicious SVG and perform Stored Cross-Site Scripting attacks against any user opening it, including administrators.

Product Status

Vendor Unknown
Product GutenKit
Versions Default: unaffected
  • affected from 0 to 2.5.0 (excl.)

Credits

  • Yaswanth Reddy Sunkara finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE