PLUGIN SECURITY

Is Gutenberg safe?

The Gutenberg plugin adds editing, customization, and site building to WordPress. Use it to test beta features before their official release.

What this plugin does

  • Slug: gutenberg
  • Author: WordPress.org
  • 300000+ active installs
  • 42/100 rating (3882 reviews on wordpress.org)
  • 51374972 all-time downloads
  • On WordPress.org since 2017-06-16

Maintenance status

  • Latest known version: 23.7.1
  • Last updated: 2026-08-19 11:08am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+

Known vulnerabilities

6 known CVEs on file for Gutenberg. Reported between 2022 and 2025.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-64354 Gutenberg [gutenberg] < 21.9.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 21.9.0 21.9.0 2025-10-25 ✓ fixed in latest
CVE-2024-37492 Gutenberg [gutenberg] < 18.6.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 18.6.1 18.6.1 2024-07-04 ✓ fixed in latest
Gutenberg [gutenberg] >= 12.9.0 - <= 18.0.0 Unknown 12.9.0–18.0.0 18.0.0 2024-04-09 ✓ fixed in latest
CVE-2023-38000 Gutenberg [gutenberg] < 16.8.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 16.8.1 16.8.1 2023-10-13 ✓ fixed in latest
Gutenberg [gutenberg] < 14.3.1 Unknown < 14.3.1 14.3.1 2022-10-18 ✓ fixed in latest
CVE-2022-43500 Gutenberg [gutenberg] < 14.3.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 14.3.1 14.3.1 2022-10-18 ✓ fixed in latest
CVE-2022-33994 Gutenberg [gutenberg] <= 17.3.0 (unfixed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Low 3.0 < 17.3.0 17.3.0 2022-07-30 ✓ fixed in latest
Gutenberg [gutenberg] < 12.7.2 Unknown < 12.7.2 12.7.2 2022-03-11 ✓ fixed in latest
+ 13 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
Gutenberg [gutenberg] < 12.7.2 Unknown < 12.7.2 12.7.2 2022-03-11 ✓ fixed in latest
Gutenberg [gutenberg] < 14.3.1 Unknown < 14.3.1 14.3.1 ✓ fixed in latest
Gutenberg [gutenberg] < 16.8.1 Unknown < 16.8.1 16.8.1 ✓ fixed in latest
Gutenberg [gutenberg] >= 12.9.0 - <= 18.0.0 Unknown 12.9.0–18.0.0 18.0.0 ✓ fixed in latest
WordPress (5.9-5.9.1) / Gutenberg (9.8.0-12.7.1) - Contributor+ Stored Cross-Site Scripting Unknown < 12.7.2 12.7.2 ✓ fixed in latest
WordPress < 5.9.2 / Gutenberg < 12.7.2 - Prototype Pollution via Gutenberg’s wordpress/url package Unknown < 12.7.2 12.7.2 ✓ fixed in latest
Gutenberg < 14.3.1 - Multiple Stored XSS Unknown < 14.3.1 14.3.1 ✓ fixed in latest
Gutenberg < 16.8.1 - Contributor+ Stored XSS Unknown < 16.8.1 16.8.1 ✓ fixed in latest
Gutenberg 12.9.0 - 18.0.0 - Unauthenticated & Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block Unknown < 18.01 18.01 ✓ fixed in latest
CVE-2024-31111 WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Template Part Block Unknown < 18.6.1 18.6.1 ✓ fixed in latest
WP 7.0.x - Unauthenticated Password Protected Post Comment Disclosure via Gutenberg Latest Comments Block Unknown < 23.7.1 23.7.1 ✓ fixed in latest
WP < 7.0.3 - Contributor+ Stored XSS via Gutenberg Post Date Block Unknown < 23.7.1 23.7.1 ✓ fixed in latest
WP < 7.0.3 - Contributor+ Stored XSS via Gutenberg Post Content Block Unknown < 23.7.1 23.7.1 ✓ fixed in latest

How to fix it

Keep Gutenberg updated — 23.7.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.