PLUGIN SECURITY
Is Gutenberg safe?
The Gutenberg plugin adds editing, customization, and site building to WordPress. Use it to test beta features before their official release.
What this plugin does
- Slug:
gutenberg - Author: WordPress.org
- 300000+ active installs
- 42/100 rating (3882 reviews on wordpress.org)
- 51374972 all-time downloads
- On WordPress.org since 2017-06-16
Maintenance status
- Latest known version: 23.7.1
- Last updated: 2026-08-19 11:08am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
Known vulnerabilities
6 known CVEs on file for Gutenberg. Reported between 2022 and 2025.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-64354 | Gutenberg [gutenberg] < 21.9.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 21.9.0 | 21.9.0 | 2025-10-25 | ✓ fixed in latest |
| CVE-2024-37492 | Gutenberg [gutenberg] < 18.6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 18.6.1 | 18.6.1 | 2024-07-04 | ✓ fixed in latest |
| — | Gutenberg [gutenberg] >= 12.9.0 - <= 18.0.0 | — | Unknown | 12.9.0–18.0.0 | 18.0.0 | 2024-04-09 | ✓ fixed in latest |
| CVE-2023-38000 | Gutenberg [gutenberg] < 16.8.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 16.8.1 | 16.8.1 | 2023-10-13 | ✓ fixed in latest |
| — | Gutenberg [gutenberg] < 14.3.1 | — | Unknown | < 14.3.1 | 14.3.1 | 2022-10-18 | ✓ fixed in latest |
| CVE-2022-43500 | Gutenberg [gutenberg] < 14.3.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 14.3.1 | 14.3.1 | 2022-10-18 | ✓ fixed in latest |
| CVE-2022-33994 | Gutenberg [gutenberg] <= 17.3.0 (unfixed) | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Low 3.0 | < 17.3.0 | 17.3.0 | 2022-07-30 | ✓ fixed in latest |
| — | Gutenberg [gutenberg] < 12.7.2 | — | Unknown | < 12.7.2 | 12.7.2 | 2022-03-11 | ✓ fixed in latest |
+ 13 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Gutenberg [gutenberg] < 12.7.2 | — | Unknown | < 12.7.2 | 12.7.2 | 2022-03-11 | ✓ fixed in latest |
| — | Gutenberg [gutenberg] < 14.3.1 | — | Unknown | < 14.3.1 | 14.3.1 | — | ✓ fixed in latest |
| — | Gutenberg [gutenberg] < 16.8.1 | — | Unknown | < 16.8.1 | 16.8.1 | — | ✓ fixed in latest |
| — | Gutenberg [gutenberg] >= 12.9.0 - <= 18.0.0 | — | Unknown | 12.9.0–18.0.0 | 18.0.0 | — | ✓ fixed in latest |
| — | WordPress (5.9-5.9.1) / Gutenberg (9.8.0-12.7.1) - Contributor+ Stored Cross-Site Scripting | — | Unknown | < 12.7.2 | 12.7.2 | — | ✓ fixed in latest |
| — | WordPress < 5.9.2 / Gutenberg < 12.7.2 - Prototype Pollution via Gutenberg’s wordpress/url package | — | Unknown | < 12.7.2 | 12.7.2 | — | ✓ fixed in latest |
| — | Gutenberg < 14.3.1 - Multiple Stored XSS | — | Unknown | < 14.3.1 | 14.3.1 | — | ✓ fixed in latest |
| — | Gutenberg < 16.8.1 - Contributor+ Stored XSS | — | Unknown | < 16.8.1 | 16.8.1 | — | ✓ fixed in latest |
| — | Gutenberg 12.9.0 - 18.0.0 - Unauthenticated & Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block | — | Unknown | < 18.01 | 18.01 | — | ✓ fixed in latest |
| CVE-2024-31111 | WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Template Part Block | — | Unknown | < 18.6.1 | 18.6.1 | — | ✓ fixed in latest |
| — | WP 7.0.x - Unauthenticated Password Protected Post Comment Disclosure via Gutenberg Latest Comments Block | — | Unknown | < 23.7.1 | 23.7.1 | — | ✓ fixed in latest |
| — | WP < 7.0.3 - Contributor+ Stored XSS via Gutenberg Post Date Block | — | Unknown | < 23.7.1 | 23.7.1 | — | ✓ fixed in latest |
| — | WP < 7.0.3 - Contributor+ Stored XSS via Gutenberg Post Content Block | — | Unknown | < 23.7.1 | 23.7.1 | — | ✓ fixed in latest |
How to fix it
Keep Gutenberg updated — 23.7.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.