CVE-2026-19698
Last modified
CVE-2026-19698 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into pages served to other users and to anonymous visitors. JavaScript execution is not possible at that role, so the impact is limited to defacement, interface redressing and forcing external resources to load.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into pages served to other users and to anonymous visitors. JavaScript execution is not possible at that role, so the impact is limited to defacement, interface redressing and forcing external resources to load.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | GutenKit | < 2.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-19698?
How severe is CVE-2026-19698?
How do I fix CVE-2026-19698?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1969The trx_addons WordPress plugin before 2.38.5 does not corre…5.3
- CVE-2026-19693extract-zip through 2.0.1 containment-checks only the parent…8.1
- CVE-2026-19694TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial…5.5
- CVE-2026-19695Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows …5.5
- CVE-2026-19696Ixia IxVeriWave and Vector Informatik BLF file parser crashe…5.5
- CVE-2026-19697The GutenKit WordPress plugin before 2.5.0 does not sanitis…6.8
- CVE-2026-19699The GutenKit WordPress plugin before 2.5.0 does not have a …2.7
- CVE-2026-1970A flaw has been found in Edimax BR-6258n up to 1.18. This is…6.1
- CVE-2026-19702Improper neutralization of special elements used in an OS co…7.8
- CVE-2026-19704The Comments WordPress plugin before 7.6.66 does not valida…5.3
- CVE-2026-19709The Membership For WooCommerce WordPress plugin before 3.1.2…5.3
- CVE-2026-1971A vulnerability has been found in Edimax BR-6288ACL up to 1.…4.8
Are you affected by CVE-2026-19698?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
