Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-08-20

CVE-2026-19699 - Gutenkit Plugin

The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.

PLUGIN Gutenkit

CVE-2026-19699

LOW CVSS 2.7 2026-08-20
Threat Entry Updated 2026-08-20

CVE-2026-19697 - Gutenkit Plugin

The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file upload capability, such as Author, to upload a malicious SVG and perform Stored Cross-Site Scripting attacks against any user opening it, including administrators.

PLUGIN Gutenkit

CVE-2026-19697

MEDIUM CVSS 6.8 2026-08-20
Scroll to top