CVE · Low

CVE-2022-33994 — Gutenberg [gutenberg] <= 17.3.0 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-33994 Gutenberg [gutenberg] <= 17.3.0 (unfixed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Low 3.0 < 17.3.0 17.3.0 2022-07-30

CVE-2022-33994

The Gutenberg plugin up to version 13.7.3 contains a stored cross-site scripting vulnerability that can be exploited by users with the Contributor role through the "Insert from URL" feature when uploading SVG documents. While the malicious script executes in a different domain context than the WordPress installation itself, the ability for lower-privilege users to embed potentially dangerous SVG files represents a security concern that some administrators may find significant, particularly since competing products restrict such uploads more strictly.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.