WP Vulnerability WatchVulnerability data as of September 24, 2026

Vulnerability alerts / September 23, 2026

Vulnerability in Getwid – Gutenberg Blocks — CVE-2026-5924

MediumSeverity
CVSS 6.4
0.3%Estimated exploit probability
EPSS
50,000+ sitesInstalls
2.2.0Fixed in

What to do now

Update Getwid – Gutenberg Blocks to 2.2.0 or later.

Affected versions

  • 2.1.3 to 2.1.3 (inclusive)

Affected: Getwid – Gutenberg Blocks (plugin, getwid)

Check: The plugin on wordpress.org / Our record for Getwid – Gutenberg Blocks

What the vulnerability is

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps block's 'customStyle' attribute in all versions up to, and including, 2.1.3. This is due to the use of eval() on user-controlled block content in the frontend JavaScript mapStyles() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

This description is reproduced verbatim from the public vulnerability record.

Sources

See other alerts