← WordPress Vulnerabilities
WordPress security by component

Gutenberg Blocks by Kadence Blocks

Gutenberg Blocks by Kadence Blocks is a WordPress component with 16 published CVE records in this archive. The latest tracked vulnerability was published Jan 24, 2025; the highest CVE/CNA score is 8.5.

Plugin slug: gutenberg-blocks-with-ai

CVE-2025-24753: Gutenberg Blocks by Kadence Blocks: A security weakness

Gutenberg Blocks by Kadence Blocks is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJan 24, 2025
Safe version guidanceSee mitigation notes
Safe version
Jan 24, 2025 CVE-2025-24753
Gutenberg Blocks by Kadence Blocks: A security weakness
Gutenberg Blocks by Kadence Blocks is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Jan 11, 2025 CVE-2024-12304
Gutenberg Blocks with AI by Kadence WP – Page Builder Features: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP – Page Builder Features is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 13, 2024 CVE-2024-12581
Gutenberg Blocks with AI by Kadence WP – Page Builder Features: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP – Page Builder Features is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Dec 12, 2024 CVE-2024-10637
Gutenberg Blocks with AI by Kadence WP: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Nov 21, 2024 CVE-2024-10785
Gutenberg Blocks with AI by Kadence WP – Page Builder Features: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP – Page Builder Features is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Aug 08, 2024 CVE-2024-6884
Gutenberg Blocks with AI by Kadence WP: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Jun 29, 2024 CVE-2024-5819
Gutenberg Blocks with AI by Kadence WP – Page Builder Features: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP – Page Builder Features is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 04, 2024 CVE-2024-4057
Gutenberg Blocks with AI by Kadence WP: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
May 15, 2024 CVE-2024-4208
Gutenberg Blocks with AI by Kadence WP – Page Builder Features: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP – Page Builder Features is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 15, 2024 CVE-2024-3189
Gutenberg Blocks by Kadence Blocks – Page Builder Features: Cross-site scripting
Gutenberg Blocks by Kadence Blocks – Page Builder Features is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
May 14, 2024 CVE-2024-4481
Gutenberg Blocks with AI by Kadence WP: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-2273
Gutenberg Blocks by Kadence Blocks – Page Builder Features: Cross-site scripting
Gutenberg Blocks by Kadence Blocks – Page Builder Features is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-0598
Gutenberg Blocks by Kadence Blocks – Page Builder Features: Cross-site scripting
Gutenberg Blocks by Kadence Blocks – Page Builder Features is affected by cross-site scripting. Exploitation requires at least editor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Apr 09, 2024 CVE-2023-6964
Gutenberg Blocks by Kadence Blocks – Page Builder Features: Server-side request forgery
Gutenberg Blocks by Kadence Blocks – Page Builder Features is affected by server-side request forgery. Exploitation requires at least contributor-level access. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE8.5
NVD6.4
Apr 05, 2024 CVE-2024-2509
Gutenberg Blocks by Kadence Blocks: Cross-site scripting
Gutenberg Blocks by Kadence Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Apr 04, 2024 CVE-2024-2919
Gutenberg Blocks by Kadence Blocks – Page Builder Features: Cross-site scripting
Gutenberg Blocks by Kadence Blocks – Page Builder Features is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4