CVE Database /
CVE-2025-47500
CVE · Medium
CVE-2025-47500 — Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.19.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-47500
|
Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.19.6 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.9
|
< 3.19.6
|
3.19.6 |
2026-01-07 |
—
|
CVE-2025-47500
The Stackable plugin for WordPress contains a security flaw in versions 3.19.5 and earlier, which allows malicious users with elevated permissions to embed unauthorized code into website content. This vulnerability arises from inadequate filtering of input data and lack of proper protection against untrusted output. As a result, authenticated attackers can inject their own scripts onto the site, which will be executed when visited by other users.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings