Gutentools

Gutentools has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Gutentools has a vendor fix available, so running the current release closes it.

All of these findings were reported by Athiwat Tiprasaharn (Jitlada). Gutentools is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.3.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Gutentools vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2026-1395

Gutentools <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Slider Block Attributes

Read the full analysis

Vulnerability Records

1 records
Gutentools banner
Latestv1.1.7
5.0(2)
100/100
Last Updated
2026-05-26 (3mo ago)
Active Installs
5,000+
Downloads
39,566
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 7.0.3
Created
2024-12-31 (2y ago)

Gutentools is a powerful block editor plugin designed for seamless full-site editing. It offers a range of customizable blocks, including page and post sliders, containers, and more, all with flexible responsive controls. With an intuitive drag-and-drop visual editor, you can easily create engaging layouts and dynamic content for any device. Unlock the full potential of WordPress with blocks that are tailored for a smooth design experience. Resources Font Icons: Author: Font Awsesome, Source: http://fontawesome.io, License: https://fontawesome.com/license (Fonts: SIL OFL 1.1, Code: MIT License) Slick: Author: Ken Wheeler, Source: https://github.com/kenwheeler/slick, License: MIT Progress Bar: Author: KaterinaLupacheva, Source: https://github.com/KaterinaLupacheva/react-progress-bar, License: MIT Jquery Countup: Author: AGMStudio, Source: https://github.com/AGMStudio/jquery.countup.js, License: MIT AcmeTicker – News Ticker: Author: codersantosh, Source: https://github.com/codersantosh/acmeticker, License: MIT External Services This plugin connects to the following external services to provide its functionality: Gutentools Demo Content API: – What it does: This API provides demo content and configuration data for the plugin’s blocks and features. – Data Sent: The plugin sends API requests to https://demos.gutentools.com/wp-json/wp/v2/ to fetch demo content and block configurations. No user-identifiable information is sent during this process. – Data Received: Demo content and configuration settings required for the plugin to work as expected. – Terms of Service: Gutentools Demo API Terms – Privacy Policy: Gutentools Demo API Privacy Policy Local File Usage: – What it does: The plugin reads block configuration files from the plugin’s directory (e.g., block.json) to dynamically register and load block settings. – Data Sent: None. The files are accessed locally on the server. – Data Received: Block configuration settings that define how the blocks behave and render. – Why it’s used: To dynamically load and register Gutenberg blocks from the plugin’s directory. Please note that by using this plugin, you agree to the terms of the external services mentioned above. Recomended Themes This plugin Supports all the Themes but the following themes are highly recommended Gutentools Gutentools Agency Gutentools Charity Biz Flick Agencygrove DigitalGrove ConsultingGrove EliteGrove NewsGrove NewsNest View More

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C