The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file upload capability, such as Author, to upload a malicious SVG and perform Stored Cross-Site Scripting attacks against any user opening it, including administrators.
CVE-2026-19697
NONE
Updated Aug 20, 2026
Unknown
unknown:gutenkit
CVE Details
CVE ID
CVE-2026-19697
Published Date
Aug 20, 2026
Vendor
Unknown
Severity
NONE
Impact
Minimal impact
Source
View Advisory