Jegstudio's vulnerability profile centers on WordPress page-builder and content-management plugins, specifically Gutenverse and Gutenverse News, with the durable signal being input-handling weaknesses in web-page generation contexts such as cross-site scripting. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jegstudio over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66065MEDIUM Missing Authorization vulnerability in Jegstudio Gutenverse gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse: from n | Nov 21, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-43920MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: f | Aug 29, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-3692MEDIUM The Gutenverse WordPress plugin before 1.9.1 does not validate the htmlTag option in various of its block before outputting it back in a page/post where the block is embed, which | May 3, 2024 | 6.1 | 18 | NO | NO |
CVE-2025-2893MEDIUM The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's countdown Block in all ve | Apr 29, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-38785MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: f | Jul 21, 2024 | 5.4 | 17 | NO | NO |
CVE-2025-5234MEDIUM The Gutenverse News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘elementId’ parameter in all versions up to, and including, 1.0.4 due to insufficient | Jun 19, 2025 | 5.4 | 16 | NO | NO |
CVE-2023-35875MEDIUM Missing Authorization vulnerability in Jegstudio Gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse: from n/a through | Dec 13, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jegstudio.
Media articles that mention a CVE ID that affects a product developed by Jegstudio — matched by CVE ID, not by vendor name.