Gutentools
Gutentools has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Gutentools has a vendor fix available, so running the current release closes it.
All of these findings were reported by Athiwat Tiprasaharn (Jitlada). Gutentools is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.3.
CVE-2026-1395Gutentools <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Slider Block Attributes
Read the full analysisVulnerability Records

Gutentools
Author
Gutentools
Gutentools is a powerful block editor plugin designed for seamless full-site editing. It offers a range of customizable blocks, including page and post sliders, containers, and more, all with flexible responsive controls. With an intuitive drag-and-drop visual editor, you can easily create engaging layouts and dynamic content for any device. Unlock the full potential of WordPress with blocks that are tailored for a smooth design experience. Resources Font Icons: Author: Font Awsesome, Source: http://fontawesome.io, License: https://fontawesome.com/license (Fonts: SIL OFL 1.1, Code: MIT License) Slick: Author: Ken Wheeler, Source: https://github.com/kenwheeler/slick, License: MIT Progress Bar: Author: KaterinaLupacheva, Source: https://github.com/KaterinaLupacheva/react-progress-bar, License: MIT Jquery Countup: Author: AGMStudio, Source: https://github.com/AGMStudio/jquery.countup.js, License: MIT AcmeTicker – News Ticker: Author: codersantosh, Source: https://github.com/codersantosh/acmeticker, License: MIT External Services This plugin connects to the following external services to provide its functionality: Gutentools Demo Content API: – What it does: This API provides demo content and configuration data for the plugin’s blocks and features. – Data Sent: The plugin sends API requests to https://demos.gutentools.com/wp-json/wp/v2/ to fetch demo content and block configurations. No user-identifiable information is sent during this process. – Data Received: Demo content and configuration settings required for the plugin to work as expected. – Terms of Service: Gutentools Demo API Terms – Privacy Policy: Gutentools Demo API Privacy Policy Local File Usage: – What it does: The plugin reads block configuration files from the plugin’s directory (e.g., block.json) to dynamically register and load block settings. – Data Sent: None. The files are accessed locally on the server. – Data Received: Block configuration settings that define how the blocks behave and render. – Why it’s used: To dynamically load and register Gutenberg blocks from the plugin’s directory. Please note that by using this plugin, you agree to the terms of the external services mentioned above. Recomended Themes This plugin Supports all the Themes but the following themes are highly recommended Gutentools Gutentools Agency Gutentools Charity Biz Flick Agencygrove DigitalGrove ConsultingGrove EliteGrove NewsGrove NewsNest View More
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C