← WordPress Vulnerabilities
WordPress security by component

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor is a WordPress component with 17 published CVE records in this archive. The latest tracked vulnerability was published Jul 10, 2026; the highest CVE/CNA score is 7.7.

Plugin slug: kadence-blocks

CVE-2026-15286: Kadence Blocks — Page Builder Toolkit for Gutenberg Editor: A security weakness

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.5.32.

PublishedJul 10, 2026
Known safe version> 3.5.32
Safe version
Jul 10, 2026 CVE-2026-15286
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor: A security weakness
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.5.32.
> 3.5.32
CVE4.3
NVDPending
Jul 01, 2026 CVE-2026-12904
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor: A security weakness
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.7.7.
> 3.7.7
CVE4.3
NVDPending
Jul 01, 2026 CVE-2026-12902
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor: A security weakness
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.7.7.
> 3.7.7
CVE4.3
NVDPending
Jun 18, 2026 CVE-2026-11357
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor: Sensitive information exposure
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 3.7.5.
> 3.7.5
CVE4.3
NVDPending
Apr 04, 2026 CVE-2026-2826
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor: A security weakness
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.6.3.
> 3.6.3
CVE4.3
NVDPending
Feb 18, 2026 CVE-2026-2633
Gutenberg Blocks with AI by Kadence WP: A security weakness
Gutenberg Blocks with AI by Kadence WP is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 18, 2026 CVE-2026-1857
Gutenberg Blocks with AI by Kadence WP: Server-side request forgery
Gutenberg Blocks with AI by Kadence WP is affected by server-side request forgery. Exploitation requires at least contributor-level access. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.3
NVDPending
Jul 09, 2025 CVE-2025-5678
Gutenberg Blocks with AI by Kadence WP – Page Builder Features: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP – Page Builder Features is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 01, 2025 CVE-2025-1291
Gutenberg Blocks with AI by Kadence WP – Page Builder Features: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP – Page Builder Features is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Nov 01, 2024 CVE-2024-9655
Gutenberg Blocks with AI by Kadence WP – Page Builder Features: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP – Page Builder Features is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 27, 2024 CVE-2024-5289
Gutenberg Blocks with AI by Kadence WP – Page Builder Features: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP – Page Builder Features is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 14, 2024 CVE-2024-4863
Gutenberg Blocks with AI by Kadence WP – Page Builder Features: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP – Page Builder Features is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 14, 2024 CVE-2024-4209
Gutenberg Blocks with AI by Kadence WP – Page Builder Features: Cross-site scripting
Gutenberg Blocks with AI by Kadence WP – Page Builder Features is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-1999
Gutenberg Blocks by Kadence Blocks – Page Builder Features: Cross-site scripting
Gutenberg Blocks by Kadence Blocks – Page Builder Features is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 02, 2024 CVE-2024-24888
Gutenberg Blocks by Kadence Blocks: Server-side request forgery
Gutenberg Blocks by Kadence Blocks is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE6.4
NVD6.5
Mar 28, 2024 CVE-2024-23500
Gutenberg Blocks by Kadence Blocks: Server-side request forgery
Gutenberg Blocks by Kadence Blocks is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE7.7
NVD6.5
Mar 13, 2024 CVE-2024-1541
Gutenberg Blocks by Kadence Blocks – Page Builder Features: Cross-site scripting
Gutenberg Blocks by Kadence Blocks – Page Builder Features is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4