Sceawere

Vulnerability Detail

CVE-2026-91862UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Getwid Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
2h ago
Vendor
jetmonsters
Product
Getwid – Gutenberg Blocks
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-image-points' parameter in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-10T06:16:44.103Z",
  "pubdate": "2026-10-10T06:16:44.103Z",
  "executiveSummary": "The Getwid – Gutenberg Blocks plugin for WordPress, in versions up to and including 3.0.1, contains a critical Stored Cross-Site Scripting (XSS) vulnerability. This security flaw stems from inadequate input validation and output encoding within the 'data-image-points' parameter handled by the plugin.\nThe vulnerability permits authenticated users with at least contributor-level privileges to inject malicious JavaScript payloads into post or page content. When a victim, such as an administrator or another site visitor, views the compromised page, the injected script executes within the context of the user's browser session.\nThe impact of successful exploitation is significant, potentially allowing an attacker to perform unauthorized actions on behalf of the victim, exfiltrate sensitive session cookies, capture CSRF tokens, or redirect users to malicious domains. Given the ubiquity of WordPress and the nature of Stored XSS, this vulnerability represents a substantial risk to site integrity and user data security. Exploitation requires no advanced server-side access, only valid credentials with sufficient permissions to edit posts or blocks within the Gutenberg editor interface.",
  "technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS), manifesting due to the improper handling of user-supplied data within the plugin's block implementation. Specifically, the 'data-image-points' parameter fails to undergo rigorous sanitization before being persisted to the WordPress database, nor does it receive context-aware output encoding when rendered on the front end.\nThe root cause lies in the application's failure to sanitize arbitrary input passed through the Gutenberg block attributes. When a user creates or modifies a post using the affected Getwid block, they can intercept the HTTP request or use the block interface to inject malicious payloads into the 'data-image-points' attribute. Because the plugin processes these attributes during the rendering phase without applying proper escaping functions—such as esc_attr() or esc_js()—the browser interprets the malicious input as active content rather than literal text.\nThe attack flow proceeds as follows: 1) An authenticated attacker with Contributor access or higher creates or edits a post utilizing the vulnerable Gutenberg block. 2) The attacker inserts a crafted payload (e.g., <script>alert('XSS')</script> or similar JavaScript vectors) into the 'data-image-points' parameter. 3) The malicious input is saved directly into the wp_posts table in the WordPress database. 4) When any user, including high-privileged administrators, navigates to the compromised post or page, the server renders the stored malicious payload into the HTML response. 5) The browser executes the injected JavaScript within the victim's security context.\nThis vulnerability is particularly dangerous because it bypasses typical filter mechanisms by leveraging block-level parameters that may be trusted by the Gutenberg editor framework. The persistence of the payload ensures that the attack is not ephemeral; it will execute every time the page is loaded by any user. Post-exploitation, an attacker can leverage the victim’s existing authentication session to perform privileged actions, such as elevating their own account permissions, modifying administrative settings, or injecting further malicious content into the WordPress environment. The lack of proper input/output control allows for arbitrary script execution, facilitating a full compromise of the user's browser-side session security."
}
CVE-2026-91862: Getwid Stored XSS Vulnerability (MEDIUM Severity, CVSS: 6.4) | Sceawere