Vulnerability in Getwid – Gutenberg Blocks — CVE-2026-91862
MediumSeverity
—Estimated exploit probability
50,000+ sitesInstalls
3.0.2Fixed in
What to do now
Update Getwid – Gutenberg Blocks to 3.0.2 or later.
Affected versions
- Everything up to and including 3.0.1
Affected: Getwid – Gutenberg Blocks (plugin, getwid)
What the vulnerability is
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-image-points' parameter in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.