Kadence blocks — page builder toolkit for gutenberg editor
This hub aggregates every CVE we track for Kadence blocks — page builder toolkit for gutenberg editor, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
29
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM28HIGH1
Monthly trend
0
0
2
1
1
0
1
0
0
0
1
0
0
0
0
0
0
3
0
1
0
1
3
2
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Kadence blocks — page builder toolkit for gutenberg editor.
- CVE-2026-18062Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content6.4
- CVE-2026-18435Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute6.4
- CVE-2026-15286Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication4.3
- CVE-2026-12902Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions4.3
- CVE-2026-12904Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter4.3
- CVE-2026-11357Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization4.3
- CVE-2026-2826Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media Upload4.3
- CVE-2026-2633Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload4.3
- CVE-2026-1857Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter4.3
- CVE-2026-2608Gutenberg Blocks by Kadence Blocks <= 3.5.32 - Missing Authorization4.3
- CVE-2025-5678Kadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter6.4
- CVE-2025-1291Gutenberg Blocks by Kadence Blocks <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon'6.4
- CVE-2024-12304Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link6.4
- CVE-2024-12581Kadence Blocks <= 3.2.53 - Authenticated (Admin+) Stored Cross-Site Scripting4.4
- CVE-2024-10785Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
Product normalization is registry-driven with AI assist and human review. How it works