Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content
medium
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block Inner Image Content in all versions up to, and including, 3.7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...
- CVSS:
- 6.4
- Affected:
- up to 3.7.8.1
- Fixed in:
- 3.7.8.2
- Disclosed:
- Jul 31, 2026
CVE-2026-18062 on NVD →
Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute
medium
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'toggleIcon' Block Attribute in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- CVSS:
- 6.4
- Affected:
- up to 3.7.8
- Fixed in:
- 3.7.8.1
- Disclosed:
- Jul 31, 2026
CVE-2026-18435 on NVD →
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.7.8 - Authenticated (Contributor+) Information Exposure
medium
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.7.8. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 3.7.8
- Fixed in:
- 3.7.8.1
- Disclosed:
- Jul 29, 2026
CVE-2026-66696 on NVD →
Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter
medium
The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 3.7.7. This is due to a mismatch between the object used for authorization and the object actually accessed in the Optimize_Rest_Controller's create_item...
- CVSS:
- 4.3
- Affected:
- up to 3.7.7
- Fixed in:
- 3.7.8
- Disclosed:
- Jun 30, 2026
CVE-2026-12904 on NVD →
Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions
medium
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with...
- CVSS:
- 4.3
- Affected:
- up to 3.7.7
- Fixed in:
- 3.7.8
- Disclosed:
- Jun 30, 2026
CVE-2026-12902 on NVD →
Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization
medium
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.5 via the editor_assets_variables. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the sit...
- CVSS:
- 4.3
- Affected:
- up to 3.7.5
- Fixed in:
- 3.7.6
- Disclosed:
- Jun 17, 2026
CVE-2026-11357 on NVD →
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media Upload
medium
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user has the `upload_files` capability in the `process_pattern` REST API endpoint. This makes it...
- CVSS:
- 4.3
- Affected:
- up to 3.6.3
- Fixed in:
- 3.6.4
- Disclosed:
- Apr 3, 2026
CVE-2026-2826 on NVD →
Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload
medium
The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.1. This is due to a missing capability check in the `process_image_data_ajax_callback()` function which handles the `kadence_import_process_image_data` AJAX action. The functi...
- CVSS:
- 4.3
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.2
- Disclosed:
- Feb 17, 2026
CVE-2026-2633 on NVD →
Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter
medium
The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.6.1. This is due to insufficient validation of the `endpoint` parameter in the `get_items()` function of the GetResponse REST API handler. The endpoint's permission check...
- CVSS:
- 4.3
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.2
- Disclosed:
- Feb 17, 2026
CVE-2026-1857 on NVD →
Gutenberg Blocks by Kadence Blocks <= 3.5.32 - Missing Authorization
medium
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.32. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform a...
- CVSS:
- 4.3
- Affected:
- up to 3.5.32
- Fixed in:
- 3.6.0
- Disclosed:
- Feb 11, 2026
CVE-2026-2608 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post publication in all versions up to, and including, 3.5.32 due to a misconfigured capability check on the 'get_items_permission_check' function permission callback of the 'process_pattern' REST API e...
- CVSS:
- 4.3
- Affected:
- up to 3.5.32
- Fixed in:
- 3.6.0
- Disclosed:
- Feb 10, 2026
CVE-2026-15286 on NVD →
Kadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘redirectURL’ parameter in all versions up to, and including, 3.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...
- CVSS:
- 6.4
- Affected:
- up to 3.5.10
- Fixed in:
- 3.5.11
- Disclosed:
- Jul 8, 2025
CVE-2025-5678 on NVD →
Gutenberg Blocks by Kadence Blocks <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon'
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icon’ parameter in all versions up to, and including, 3.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with C...
- CVSS:
- 6.4
- Affected:
- up to 3.4.9
- Fixed in:
- 3.4.10
- Disclosed:
- Feb 28, 2025
CVE-2025-1291 on NVD →
Gutenberg Blocks by Kadence Blocks <= 3.3.1 - Missing Authorization
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to perfor...
- CVSS:
- 4.3
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.2
- Disclosed:
- Jan 24, 2025
CVE-2025-24753 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.3.2
unknown
[en] Missing Authorization vulnerability in Kadence WP Gutenberg Blocks by Kadence Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.3.1.
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.2
- Disclosed:
- Jan 24, 2025
CVE-2025-24753 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.4.3
unknown
[en] The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via button block link in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Jan 11, 2025
CVE-2024-12304 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via button block link in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Cont...
- CVSS:
- 6.4
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.3
- Disclosed:
- Jan 10, 2025
CVE-2024-12304 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.54
unknown
[en] The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with a...
- Affected:
- up to 3.2.54
- Fixed in:
- 3.2.54
- Disclosed:
- Dec 13, 2024
CVE-2024-12581 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.54
unknown
[en] The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.54 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 3.2.54
- Fixed in:
- 3.2.54
- Disclosed:
- Dec 12, 2024
CVE-2024-10637 on NVD →
Kadence Blocks <= 3.2.53 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.2.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access...
- CVSS:
- 6.4
- Affected:
- up to 3.2.53
- Fixed in:
- 3.2.54
- Disclosed:
- Nov 21, 2024
CVE-2024-10637 on NVD →
Kadence Blocks <= 3.2.53 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admini...
- CVSS:
- 4.4
- Affected:
- up to 3.2.53
- Fixed in:
- 3.2.54
- Disclosed:
- Nov 21, 2024
CVE-2024-12581 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.3.4
unknown
[en] The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- Affected:
- up to 3.3.4
- Fixed in:
- 3.3.4
- Disclosed:
- Nov 21, 2024
CVE-2024-10785 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.4
- Disclosed:
- Nov 20, 2024
CVE-2024-10785 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.3.2
unknown
[en] The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl...
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.2
- Disclosed:
- Nov 1, 2024
CVE-2024-9655 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Widget
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...
- CVSS:
- 6.4
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.2
- Disclosed:
- Oct 31, 2024
CVE-2024-9655 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.39
unknown
[en] The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 3.2.39
- Fixed in:
- 3.2.39
- Disclosed:
- Aug 8, 2024
CVE-2024-6884 on NVD →
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Block in all versions up to, and including, 3.2.38 due to insufficient input sanitization and output escaping on the Days Label. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 3.2.28
- Fixed in:
- 3.2.39
- Disclosed:
- Jul 18, 2024
CVE-2024-6884 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.46
unknown
[en] The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data attributes in all versions up to, and including, 3.2.45 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...
- Affected:
- up to 3.2.46
- Fixed in:
- 3.2.46
- Disclosed:
- Jun 29, 2024
CVE-2024-5819 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.45 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data Attributes
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data attributes in all versions up to, and including, 3.2.45 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possi...
- CVSS:
- 6.4
- Affected:
- up to 3.2.45
- Fixed in:
- 3.2.46
- Disclosed:
- Jun 28, 2024
CVE-2024-5819 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.43
unknown
[en] The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget parameters in all versions up to, and including, 3.2.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticate...
- Affected:
- up to 3.2.43
- Fixed in:
- 3.2.43
- Disclosed:
- Jun 27, 2024
CVE-2024-5289 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.42 - Authenticated (Contributor+) Stored Cross-Site Scripting in Google Maps Widget
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget parameters in all versions up to, and including, 3.2.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...
- CVSS:
- 6.4
- Affected:
- up to 3.2.42
- Fixed in:
- 3.2.43
- Disclosed:
- Jun 26, 2024
CVE-2024-5289 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.39
unknown
[en] The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘titleFont’ parameter in all versions up to, and including, 3.2.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...
- Affected:
- up to 3.2.39
- Fixed in:
- 3.2.39
- Disclosed:
- Jun 14, 2024
CVE-2024-4863 on NVD →
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via titleFont Parameter
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘titleFont’ parameter in all versions up to, and including, 3.2.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 3.2.38
- Fixed in:
- 3.2.39
- Disclosed:
- Jun 13, 2024
CVE-2024-4863 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.37
unknown
[en] The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.37 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 3.2.37
- Fixed in:
- 3.2.37
- Disclosed:
- Jun 4, 2024
CVE-2024-4057 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.38
unknown
[en] The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Testimonial', 'Progress Bar', 'Lottie Animations', 'Row Layout', 'Google Maps', and 'Advanced Gallery' blocks in all versions up to, and including, 3.2.37 due to insuff...
- Affected:
- up to 3.2.38
- Fixed in:
- 3.2.38
- Disclosed:
- May 15, 2024
CVE-2024-3189 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.38
unknown
[en] The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the typer effect in the advanced heading widget in all versions up to, and including, 3.2.37 due to insufficient input sanitization and output escaping on user supplied attribute...
- Affected:
- up to 3.2.38
- Fixed in:
- 3.2.38
- Disclosed:
- May 15, 2024
CVE-2024-4208 on NVD →
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fileUrl attribute in versions up to, and including 3.2.36, due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...
- CVSS:
- 6.4
- Affected:
- up to 3.2.36
- Fixed in:
- 3.2.37
- Disclosed:
- May 14, 2024
CVE-2024-4057 on NVD →
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typer Effect
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the typer effect in the advanced heading widget in all versions up to, and including, 3.2.37 due to insufficient input sanitization and output escaping on user supplied attributes. Th...
- CVSS:
- 6.4
- Affected:
- up to 3.2.37
- Fixed in:
- 3.2.38
- Disclosed:
- May 14, 2024
CVE-2024-4208 on NVD →
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Testimonial', 'Progress Bar', 'Lottie Animations', 'Row Layout', 'Google Maps', and 'Advanced Gallery' blocks in all versions up to, and including, 3.2.37 due to insufficien...
- CVSS:
- 5.4
- Affected:
- up to 3.2.37
- Fixed in:
- 3.2.38
- Disclosed:
- May 14, 2024
CVE-2024-3189 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.37
unknown
[en] The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown timer in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible fo...
- Affected:
- up to 3.2.37
- Fixed in:
- 3.2.37
- Disclosed:
- May 11, 2024
CVE-2024-4209 on NVD →
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown timer in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut...
- CVSS:
- 6.4
- Affected:
- up to 3.2.36
- Fixed in:
- 3.2.37
- Disclosed:
- May 10, 2024
CVE-2024-4209 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.37
unknown
[en] The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the plugin's blocks in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible fo...
- Affected:
- up to 3.2.37
- Fixed in:
- 3.2.37
- Disclosed:
- May 10, 2024
CVE-2024-4481 on NVD →
Gutenberg Blocks with AI by Kadence WP <= 3.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Link
medium
The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the plugin's blocks in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut...
- CVSS:
- 6.4
- Affected:
- up to 3.2.36
- Fixed in:
- 3.2.37
- Disclosed:
- May 9, 2024
CVE-2024-4481 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.35
unknown
[en] The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 3.2.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with c...
- Affected:
- up to 3.2.35
- Fixed in:
- 3.2.35
- Disclosed:
- May 2, 2024
CVE-2024-2273 on NVD →
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.34 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 3.2.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contri...
- CVSS:
- 6.4
- Affected:
- up to 3.2.34
- Fixed in:
- 3.2.35
- Disclosed:
- May 1, 2024
CVE-2024-2273 on NVD →
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF)
high
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.26 via the 'kadence_import_get_new_connection_data' AJAX action. This makes it possible for authenticated attackers, with contributor-level access an...
- CVSS:
- 8.5
- Affected:
- up to 3.1.26
- Fixed in:
- 3.2.12
- Disclosed:
- Apr 9, 2024
CVE-2023-6964 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.26
unknown
- Affected:
- up to 3.2.26
- Fixed in:
- 3.2.26
- Disclosed:
- Apr 9, 2024
CVE-2024-2866 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.12
unknown
[en] The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.26 via the 'kadence_import_get_new_connection_data' AJAX action. This makes it possible for authenticated attackers, with contributor-level acce...
- Affected:
- up to 3.2.12
- Fixed in:
- 3.2.12
- Disclosed:
- Apr 9, 2024
CVE-2023-6964 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.18
unknown
[en] The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form message settings in all versions up to and including 3.2.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...
- Affected:
- up to 3.2.18
- Fixed in:
- 3.2.18
- Disclosed:
- Apr 9, 2024
CVE-2024-0598 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.26
unknown
[en] The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget's anchor style parameter in all versions up to, and including, 3.2.25 due to insufficient input sanitization and output escaping. This makes it possible for au...
- Affected:
- up to 3.2.26
- Fixed in:
- 3.2.26
- Disclosed:
- Apr 9, 2024
CVE-2024-1999 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.26
unknown
[en] The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 3.2.26
- Fixed in:
- 3.2.26
- Disclosed:
- Apr 5, 2024
CVE-2024-2509 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.32
unknown
[en] The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CountUp Widget in all versions up to, and including, 3.2.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut...
- Affected:
- up to 3.2.32
- Fixed in:
- 3.2.32
- Disclosed:
- Apr 4, 2024
CVE-2024-2919 on NVD →
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via CountUp Widget
medium
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CountUp Widget in all versions up to, and including, 3.2.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti...
- CVSS:
- 6.4
- Affected:
- up to 3.2.31
- Fixed in:
- 3.2.32
- Disclosed:
- Apr 3, 2024
CVE-2024-2919 on NVD →
Gutenberg Blocks by Kadence Blocks <= 3.2.17 - Authenticated(Editor+) Stored Cross-Site Scripting via Contact Form Message Settings
medium
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form message settings in all versions up to and including 3.2.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...
- CVSS:
- 4.4
- Affected:
- up to 3.2.17
- Fixed in:
- 3.2.18
- Disclosed:
- Apr 2, 2024
CVE-2024-0598 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.26
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Kadence WP Gutenberg Blocks by Kadence Blocks.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.2.25.
- Affected:
- up to 3.2.26
- Fixed in:
- 3.2.26
- Disclosed:
- Apr 2, 2024
CVE-2024-24888 on NVD →
Gutenberg Blocks by Kadence Blocks <= 3.2.25 - Authenticated (Author+) Server-Side Request Forgery
medium
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.25. This makes it possible for authenticated attackers, with author-level access and above, to make web requests to arbitrary locations originating f...
- CVSS:
- 6.4
- Affected:
- up to 3.2.25
- Fixed in:
- 3.2.26
- Disclosed:
- Mar 29, 2024
CVE-2024-24888 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.20
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Kadence WP Gutenberg Blocks by Kadence Blocks.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.2.19.
- Affected:
- up to 3.2.20
- Fixed in:
- 3.2.20
- Disclosed:
- Mar 28, 2024
CVE-2024-23500 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.19 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.19. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations orig...
- CVSS:
- 6.4
- Affected:
- up to 3.2.19
- Fixed in:
- 3.2.20
- Disclosed:
- Mar 26, 2024
CVE-2024-23500 on NVD →
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Widget
medium
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget's anchor style parameter in all versions up to, and including, 3.2.25 due to insufficient input sanitization and output escaping. This makes it possible for authent...
- CVSS:
- 6.4
- Affected:
- up to 3.2.25
- Fixed in:
- 3.2.26
- Disclosed:
- Mar 21, 2024
CVE-2024-1999 on NVD →
Gutenberg Blocks by Kadence Blocks <= 3.2.25 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Form widget in all versions up to, and including, 3.2.25 due to insufficient input sanitization and output escaping on user supplied attributes such as 'placeholder'...
- CVSS:
- 6.4
- Affected:
- up to 3.2.25
- Fixed in:
- 3.2.26
- Disclosed:
- Mar 15, 2024
CVE-2024-2509 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.2.24
unknown
[en] The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the htmlTag attribute in all versions up to, and including, 3.2.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wit...
- Affected:
- up to 3.2.24
- Fixed in:
- 3.2.24
- Disclosed:
- Mar 13, 2024
CVE-2024-1541 on NVD →
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.23 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the htmlTag attribute in all versions up to, and including, 3.2.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with con...
- CVSS:
- 6.4
- Affected:
- up to 3.2.23
- Fixed in:
- 3.2.24
- Disclosed:
- Mar 1, 2024
CVE-2024-1541 on NVD →
Kadence Blocks <= 3.1.10 - Unauthenticated Arbitrary File Upload
critical
The Kadence Blocks for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_fields function in versions up to, and including, 3.1.10. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code ex...
- CVSS:
- 9.8
- Affected:
- up to 3.1.11
- Fixed in:
- 3.1.11
- Disclosed:
- Aug 9, 2023
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.1.11
unknown
The Kadence Blocks for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_fields function in versions up to, and including, 3.1.10. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code ex...
- Affected:
- up to 3.1.11
- Fixed in:
- 3.1.11
- Disclosed:
- Aug 9, 2023
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.1.11
unknown
Update the WordPress Gutenberg Blocks by Kadence Blocks plugin to the latest available version (at least 3.1.11).
An unknown person discovered and reported this Arbitrary File Upload vulnerability in WordPress Gutenberg Blocks by Kadence Blocks Plugin. This could allow a malicious actor to upload any type of file to yo...
- Affected:
- up to 3.1.11
- Fixed in:
- 3.1.11
- Disclosed:
- Aug 9, 2023
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.4.10
unknown
- Affected:
- up to 3.4.10
- Fixed in:
- 3.4.10
CVE-2025-1291 on NVD →
Gutenberg Blocks with AI by Kadence WP – Page Builder Features [kadence-blocks] < 3.5.11
unknown
- Affected:
- up to 3.5.11
- Fixed in:
- 3.5.11
CVE-2025-5678 on NVD →