Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2026-08-20
CVE-2026-19699 - Gutenkit Plugin
The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.
PLUGIN
Gutenkit
CVE-2026-19699
Risk Score
Threat Entry
Updated 2026-08-20
CVE-2026-19697 - Gutenkit Plugin
The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file upload capability, such as Author, to upload a malicious SVG and perform Stored Cross-Site Scripting attacks against any user opening it, including administrators.
PLUGIN
Gutenkit
CVE-2026-19697
Risk Score
