🔐 CVE Alert

CVE-2025-14984

MEDIUM 6.4

Gutenverse Form <= 2.3.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
0th

The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.3.2. This is due to the plugin's framework component adding SVG to the allowed MIME types via the upload_mimes filter without implementing any sanitization of SVG file contents. This makes it possible for authenticated attackers, with Author-level access and above, to upload SVG files containing malicious JavaScript that executes when the file is viewed, leading to arbitrary JavaScript execution in victims' browsers.

CWE CWE-79
Vendor jegstudio
Product gutenverse form – contact form builder, booking, reservation, subscribe for block editor
Published Jan 8, 2026
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for jegstudio gutenverse form – contact form builder, booking, reservation, subscribe for block editor

Be the first to know when new medium vulnerabilities affecting jegstudio gutenverse form – contact form builder, booking, reservation, subscribe for block editor are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

jegstudio / Gutenverse Form – Contact Form Builder, Booking, Reservation, Subscribe for Block Editor
0 ≤ 2.3.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/792fa6cb-e55a-4f68-b8a8-9039fb1ff694?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/gutenverse-form/tags/2.3.2/lib/framework/includes/class-init.php#L837 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/gutenverse-form/tags/2.3.2/lib/framework/includes/class-init.php#L169 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3427504/gutenverse-form/trunk/lib/framework/includes/class-init.php?old=3395520&old_path=gutenverse-form%2Ftrunk%2Flib%2Fframework%2Fincludes%2Fclass-init.php

Credits

andrea bocchetti