Gutenverse Form – Contact Form Builder, Block Form & Booking Form Security & Risk Analysis

wordpress.org/plugins/gutenverse-form

Contact form builder for WordPress: create block forms, booking forms, reservation forms, subscribe forms, and custom forms.

10K active installs v2.8.2 PHP 7.0+ WP 5.9+ Updated Jun 23, 2026
block-formbooking-formcontact-formformform-builder
93
A · Safe
CVEs total4
Unpatched0
Last CVEJun 24, 2026
Safety Verdict

Is Gutenverse Form – Contact Form Builder, Block Form & Booking Form Safe to Use in 2026?

Generally Safe

Score 93/100

Gutenverse Form – Contact Form Builder, Block Form & Booking Form has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

4 known CVEsLast CVE: Jun 24, 2026Updated 2mo ago
Risk Assessment

The Gutenverse Form plugin version 2.5.1 exhibits a mixed security posture. On the positive side, the static analysis reveals excellent adherence to secure coding practices in several key areas. There are no identified dangerous functions, all SQL queries utilize prepared statements, and a high percentage of output is properly escaped, indicating a strong defense against common injection vulnerabilities. Furthermore, the presence of nonce and capability checks, along with a lack of bundled libraries, reduces the attack surface and reliance on potentially vulnerable third-party code. However, significant concerns arise from the plugin's vulnerability history, which includes three previously discovered medium-severity vulnerabilities. The nature of these past vulnerabilities, specifically Cross-site Scripting and Missing Authorization, suggests potential recurring weaknesses in input sanitization and access control. The fact that these vulnerabilities are marked as 'currently unpatched' in the historical data, despite the most recent one being in the future, is a temporal anomaly that warrants attention, suggesting a pattern of past security oversights.

While the current version's code analysis doesn't show immediate critical flaws like unsanitized taint flows or a large attack surface, the historical context of medium-severity vulnerabilities, particularly XSS and authorization issues, cannot be ignored. This history implies that the plugin's developers may struggle with consistently implementing robust input validation and authorization checks. The absence of any identified vulnerabilities in the current static analysis is positive, but it's crucial to consider the historical trend. The plugin's strengths lie in its diligent use of prepared statements and output escaping, but its past vulnerabilities in XSS and authorization present a persistent risk that requires ongoing vigilance and thorough code review. The presence of file operations and external HTTP requests, while not flagged as problematic in the static analysis, are always potential vectors for exploitation if not handled with extreme care.

Key Concerns

  • Total known CVEs: 3 (medium severity)
  • Common vulnerability types: XSS, Missing Authorization
  • Output escaping: 87% properly escaped (13% unescaped)
  • File operations present
  • External HTTP requests present
Vulnerabilities
4 published

Gutenverse Form – Contact Form Builder, Block Form & Booking Form Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
2 CVEs in 2026
2026
Patched Has unpatched

Severity Breakdown

High
1
Medium
3

4 total CVEs

CVE-2026-56040high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gutenverse Form – Contact Form Builder, Block Form & Booking Form <= 2.4.7 - Unauthenticated Stored Cross-Site Scripting

Jun 24, 2026 Patched in 2.5.0 (6d)
CVE-2025-14984medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gutenverse Form <= 2.3.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

Jan 7, 2026 Patched in 2.4.0 (1d)
CVE-2025-68511medium · 4.3Missing Authorization

Gutenverse Form <= 2.3.1 - Missing Authorization

Dec 20, 2025 Patched in 2.3.2 (18d)
CVE-2025-66079medium · 4.3Missing Authorization

Gutenverse Form <= 2.2.0 - Missing Authorization

Nov 28, 2025 Patched in 2.3.0 (4d)
Version History

Gutenverse Form – Contact Form Builder, Block Form & Booking Form Release Timeline

v2.8.2Current
v2.8.1
v2.8.0
v2.7.1
v2.7.0
v2.6.3
v2.6.2
v2.6.1
v2.6.0
v2.5.3
v2.5.1
v2.5.0
v2.4.71 CVE
v2.4.51 CVE
v2.4.41 CVE
v2.4.31 CVE
v2.4.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Gutenverse Form – Contact Form Builder, Block Form & Booking Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
45 escaped
Nonce Checks
1
Capability Checks
1
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

87% escaped52 total outputs
Attack Surface

Gutenverse Form – Contact Form Builder, Block Form & Booking Form Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 37
actioninitincludes\class-blocks.php:22
filtergutenverse_block_categoriesincludes\class-blocks.php:23
filtergutenverse_dashboard_configincludes\class-dashboard.php:22
filtergutenverse_include_dashboardincludes\class-dashboard.php:23
filtergutenverse_block_configincludes\class-editor-assets.php:22
actiongutenverse_include_blockincludes\class-editor-assets.php:23
actioninitincludes\class-entries.php:29
actionadmin_enqueue_scriptsincludes\class-entries.php:30
actionadd_meta_boxesincludes\class-entries.php:31
actionpre_get_postsincludes\class-entries.php:33
actionrestrict_manage_postsincludes\class-entries.php:34
filterpost_row_actionsincludes\class-entries.php:38
filterhidden_meta_boxesincludes\class-entries.php:39
filterposts_joinincludes\class-entries.php:40
filterposts_whereincludes\class-entries.php:41
filterposts_groupbyincludes\class-entries.php:42
actionwp_enqueue_scriptsincludes\class-form-validation.php:54
filtergutenverse_bypass_generate_styleincludes\class-form-validation.php:55
actiongutenverse_loop_blocksincludes\class-form-validation.php:56
actiongutenverse_after_style_loop_blocksincludes\class-form-validation.php:57
actioninitincludes\class-form.php:32
actionadmin_enqueue_scriptsincludes\class-form.php:33
actionadmin_footerincludes\class-form.php:34
actionadmin_menuincludes\class-form.php:36
filterpost_row_actionsincludes\class-form.php:37
filtergutenverse_include_frontendincludes\class-frontend-assets.php:22
filtergutenverse_include_frontendincludes\class-frontend-assets.php:23
filtergutenverse_conditional_script_attributesincludes\class-frontend-assets.php:24
actiongutenverse_setting_toolbarincludes\class-frontend-toolbar.php:22
actionplugins_loadedincludes\class-init.php:121
actionplugins_loadedincludes\class-init.php:123
filtergutenverse_companion_plugin_listincludes\class-init.php:124
actionrest_api_initincludes\class-init.php:247
filtergutenverse_dashboard_configincludes\class-init.php:319
actiongutenverse_check_updateincludes\class-meta-option.php:24
actiongutenverse_initial_meta_optionincludes\class-meta-option.php:25
filtergutenverse_block_style_instanceincludes\class-style-generator.php:51
Maintenance & Trust

Gutenverse Form – Contact Form Builder, Block Form & Booking Form Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedJun 23, 2026
PHP min version7.0
Downloads276K

Community Trust

Rating100/100
Number of ratings1
Active installs10K
Developer Profile

Gutenverse Form – Contact Form Builder, Block Form & Booking Form Developer Profile

Jegstudio

6 plugins · 49K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
18 days
View full developer profile
Detection Fingerprints

How We Detect Gutenverse Form – Contact Form Builder, Block Form & Booking Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gutenverse-form/assets/js/blocks.js/wp-content/plugins/gutenverse-form/assets/js/dashboard.js/wp-content/plugins/gutenverse-form/assets/css/update-notice.css/wp-content/plugins/gutenverse-form/assets/css/blocks.css/wp-content/plugins/gutenverse-form/assets/css/form.css
Script Paths
/wp-content/plugins/gutenverse-form/assets/js/blocks.js/wp-content/plugins/gutenverse-form/assets/js/dashboard.js
Version Parameters
gutenverse-form/assets/js/blocks.js?ver=gutenverse-form/assets/js/dashboard.js?ver=gutenverse-form/assets/css/update-notice.css?ver=gutenverse-form/assets/css/blocks.css?ver=gutenverse-form/assets/css/form.css?ver=

HTML / DOM Fingerprints

CSS Classes
gutenverse-form-blocksgutenverse-form-dashboardgutenverse-entries
Data Attributes
gutenverseFormAssetURLgutenverseFormImgDir
JS Globals
gutenverseFormAssetURLgutenverseFormImgDir
FAQ

Frequently Asked Questions about Gutenverse Form – Contact Form Builder, Block Form & Booking Form