CVE-2023-38000: WordPress Gutenberg

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.

Affected products

  • WordPress Gutenberg: up to and including 16.8.0
  • WordPress WordPress: from 5.9, up to and including 5.9.7; from 6.0, up to and including 6.0.5; from 6.1, up to and including 6.1.3; from 6.2, up to and including 6.2.2; from 6.3, up to and including 6.3.1

Published 2023-10-13. Last modified 2026-06-17.