Vulnerability Description
The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into pages served to other users and to anonymous visitors. JavaScript execution is not possible at that role, so the impact is limited to defacement, interface redressing and forcing external resources to load.
CVSS Score
LOW
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-19698?
CVE-2026-19698 is a vulnerability with a CVSS score of 3.5 (LOW). The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, allowing users with the Contr...
How severe is CVE-2026-19698?
CVE-2026-19698 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-19698?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.