CVE · Medium

CVE-2025-47500 — Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.19.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-47500 Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.19.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 3.19.6 3.19.6 2026-01-07

CVE-2025-47500

The Stackable plugin for WordPress contains a security flaw in versions 3.19.5 and earlier, which allows malicious users with elevated permissions to embed unauthorized code into website content. This vulnerability arises from inadequate filtering of input data and lack of proper protection against untrusted output. As a result, authenticated attackers can inject their own scripts onto the site, which will be executed when visited by other users.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.