WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Gutenberg

The Gutenberg plugin adds editing, customization, and site building to WordPress. Use it to test beta features before their official release.

6Reported vulnerabilities
6.4Highest CVSS score
23.7.2Latest version
300,000+Active installs

What to do now

Update Gutenberg to 21.9.0 or later. 5 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 11, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-38000 Medium 5.4 0.8% 16.8.0 and earlier 6.3.2 October 13, 2023
CVE-2022-33994 Low 3 0.7% 13.7.3 and earlier July 30, 2022
CVE-2022-43500 Medium 6.4 0.7% 14.3.0 and earlier 14.3.1 October 18, 2022
CVE-2025-64354 Medium 6.4 0.2% 21.8.2 and earlier 21.9.0 October 25, 2025
WF-63f26380-0bc2-4fe7-9e9d-05c688c201f9 Medium 6.4 12.9.0 to 18.0.0 (inclusive) 18.01 April 9, 2024
WF-954b8064-f317-4af4-a55f-9a61ee945006 Medium 5.4 Before 12.7.2 12.7.2 March 11, 2022

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.