Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Gutenberg — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
gutenberg
- 300000+ instalaciones activas
Estado de mantenimiento
- Última versión conocida: 23.5.3
- Requiere PHP: 7.4+
Vulnerabilidades conocidas
4 CVEs conocidos registrados para Gutenberg.
Reportadas entre 2022 y 2025.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2025-64354
|
Gutenberg [gutenberg] < 21.9.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 21.9.0
|
21.9.0 |
2025-10-25 |
✓ corregido en la última versión
|
|
CVE-2024-37492
|
Gutenberg [gutenberg] < 18.6.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 18.6.1
|
18.6.1 |
2024-07-04 |
✓ corregido en la última versión
|
|
—
|
Gutenberg [gutenberg] >= 12.9.0 - <= 18.0.0 |
— |
Desconocido
|
12.9.0–18.0.0
|
18.0.0 |
2024-04-09 |
✓ corregido en la última versión
|
|
CVE-2023-38000
|
Gutenberg [gutenberg] < 16.8.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 16.8.1
|
16.8.1 |
2023-10-13 |
✓ corregido en la última versión
|
|
—
|
Gutenberg [gutenberg] < 14.3.1 |
— |
Desconocido
|
< 14.3.1
|
14.3.1 |
2022-10-18 |
✓ corregido en la última versión
|
|
—
|
Gutenberg [gutenberg] < 14.3.1 |
— |
Desconocido
|
< 14.3.1
|
14.3.1 |
2022-10-18 |
✓ corregido en la última versión
|
|
CVE-2022-33994
|
Gutenberg [gutenberg] <= 17.3.0 (unfixed) |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Baja
3,0
|
< 17.3.0
|
17.3.0 |
2022-07-30 |
✓ corregido en la última versión
|
|
—
|
Gutenberg [gutenberg] < 12.7.2 |
— |
Desconocido
|
< 12.7.2
|
12.7.2 |
2022-03-11 |
✓ corregido en la última versión
|
CVE-2025-64354
The Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 21.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-37492
<p>WordPress Gutenberg Plugin <= 18.6.0 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Gutenberg</p><p>Link: https://wordpress.org/plugins/gutenberg/#developers</p><p>Affected Version <= 18.6.0</p><p>Fixed in version 18.6.1 </p>
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Gutenberg [gutenberg] >= 12.9.0 - <= 18.0.0
The Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in versions 12.9.0 to 18.0.0 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. In addition, it also makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that have the comment block present and display the comment author's avatar.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-38000
Update the WordPress Gutenberg plugin to the latest available version (at least 16.8.1).
Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gutenberg Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 16.8.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Gutenberg [gutenberg] < 14.3.1
Multiple Stored Cross-Site Scripting (XSS) vulnerabilities via Search, Feature Image, RSS, and Widget blocks were discovered by Alex Concha (WP Security team) and a third-party audit in the WordPress Gutenberg plugin (versions <= 14.3.1).
Update the WordPress Gutenberg plugin to the latest available version (at least 14.3.1).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Gutenberg [gutenberg] < 14.3.1
WordPress Core in versions up to 6.0.3 and the Gutenberg plugin for WordPress in versions up to 14.3.1 are vulnerable to Stored Cross-Site Scripting due to insufficient output escaping on user supplied input. The RSS widget, Search Block, Featured Image Block, RSS Block, and Navigation Block are all affected components. This makes it possible for authenticated users with access to the block editor to inject malicious web scripts that may execute whenever accessing the page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-33994
The Gutenberg plugin for WordPress has been reported to be vulnerable to Stored Cross-Site Scripting in versions up to, and including, 13.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to embed remote SVG files as images in blog posts. As these files use <img> tags, no code can be executed in the context of the WordPress site. However, if the attacker can get a victim to visit the remotely hosted SVG file then any JavaScript in that file will execute in their browser in the context of the remote site.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Gutenberg [gutenberg] < 12.7.2
Stored Cross-Site Scripting (XSS) vulnerability discovered by Ben Bidner in WordPress Gutenberg plugin (versions <= 12.7.1).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
+ 4 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
—
|
Gutenberg [gutenberg] < 12.7.2 |
— |
Desconocido
|
< 12.7.2
|
12.7.2 |
2022-03-11 |
✓ corregido en la última versión
|
|
—
|
Gutenberg [gutenberg] < 14.3.1 |
— |
Desconocido
|
< 14.3.1
|
14.3.1 |
— |
✓ corregido en la última versión
|
|
—
|
Gutenberg [gutenberg] < 16.8.1 |
— |
Desconocido
|
< 16.8.1
|
16.8.1 |
— |
✓ corregido en la última versión
|
|
—
|
Gutenberg [gutenberg] >= 12.9.0 - <= 18.0.0 |
— |
Desconocido
|
12.9.0–18.0.0
|
18.0.0 |
— |
✓ corregido en la última versión
|
Gutenberg [gutenberg] < 12.7.2
WordPress Core in various versions < 5.9.2 and Gutenberg versions less than 12.7.2 are vulnerable to prototype pollution via the block editor which could make injecting malicious web scripts possible in some cases.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Gutenberg [gutenberg] < 14.3.1
The plugin does not escape data from some blocks before outputting ti back in pages, which could lead to Stored XSS issues.
Affected blocks: Search, Feature Image, RSS and Widget
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Gutenberg [gutenberg] < 16.8.1
The plugin does not adequately escape the content of the footnotes within the paragraph block of the block editor, leading to a Contributor+ Cross-Site Scripting vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Gutenberg [gutenberg] >= 12.9.0 - <= 18.0.0
Update the WordPress Gutenberg plugin to the latest available version (at least 18.1.0).
John Blackbourn discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gutenberg Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 18.1.0.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Cómo solucionarlo
Mantén Gutenberg actualizado — 23.5.3 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.