VDB
CVE-2025-53324
CVE-2025-53324
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeYatri Gutenify gutenify allows Stored XSS.This issue affects Gutenify: from n/a through <= 1.5.7.
EPSS 0.03% · 9.5th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.03%
9.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| CodeYatri | Gutenify | 0 |
Exploit Intelligence
- https://patchstack.com/database/Wordpress/Plugin/gutenify/vulnerability/wordpress-gutenify-plugin-1-5-6-cross-site-scripting-xss-vulnerability?_s_id=cve (circl)
- https://patchstack.com/database/wordpress/plugin/gutenify/vulnerability/wordpress-gutenify-plugin-1-5-6-cross-site-scripting-xss-vulnerability (vulncheck)
- CVE-2025-38126.yara (github-yara)
- CVE-2025-38126.yara (github-yara)
- CVE-2025-38126.yara (github-yara)
- CVE-2025-38126.yara (github-yara)
- CVE-2025-38126.yara (github-yara)
- CVE-2025-38126.yara (github-yara)
- CVE-2025-38097.yara (github-yara)
- CVE-2025-38097.yara (github-yara)
…and 127 more exploits
Timeline
- Sep 23, 2025 VulnCheck KEV Exploitation
- Oct 12, 2025 PoC Published
- Oct 16, 2025 PoC Published
- Oct 17, 2025 PoC Published
- Oct 21, 2025 PoC Published
- Oct 24, 2025 PoC Published
- Oct 24, 2025 PoC Published
- Oct 24, 2025 PoC Published
- Oct 24, 2025 PoC Published
- Oct 27, 2025 PoC Published
- Nov 6, 2025 CVE Published
- Nov 7, 2025 EPSS Score
References
- https://patchstack.com/database/Wordpress/Plugin/gutenify/vulnerability/wordpress-gutenify-plugin-1-5-6-cross-site-scripting-xss-vulnerability?_s_id=cve vdb
- https://nvd.nist.gov/vuln/detail/CVE-2025-53324 advisory
- https://vdp.patchstack.com/database/Wordpress/Plugin/gutenify/vulnerability/wordpress-gutenify-plugin-1-5-6-cross-site-scripting-xss-vulnerability url
- https://vdp.patchstack.com/database/Wordpress/Plugin/gutenify/vulnerability/wordpress-gutenify-plugin-1-5-6-cross-site-scripting-xss-vulnerability?_s_id=cve url