CVE Tools

Kadence Blocks — Page Builder Toolkit For Gutenberg Editor

29 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Kadence Blocks — Page Builder Toolkit For Gutenberg Editor, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Kadence Blocks — Page Builder Toolkit For Gutenberg Editor CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Kadence Blocks — Page Builder Toolkit For Gutenberg Editor CVEs per month
MonthCVEs
2024-100
2024-112
2024-121
2025-011
2025-020
2025-031
2025-040
2025-050
2025-060
2025-071
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-023
2026-030
2026-041
2026-050
2026-061
2026-073
2026-082
2026-090

Severity

How the 29 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High13%
  • Medium2897%

Latest CVEs

The 15 most recently published vulnerabilities affecting Kadence Blocks — Page Builder Toolkit For Gutenberg Editor.

  1. CVE-2026-18435Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute6.4
  2. CVE-2026-18062Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content6.4
  3. CVE-2026-15286Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication4.3
  4. CVE-2026-12902Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions4.3
  5. CVE-2026-12904Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter4.3
  6. CVE-2026-11357Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization4.3
  7. CVE-2026-2826Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media Upload4.3
  8. CVE-2026-2633Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload4.3
  9. CVE-2026-1857Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter4.3
  10. CVE-2026-2608Gutenberg Blocks by Kadence Blocks <= 3.5.32 - Missing Authorization4.3
  11. CVE-2025-5678Kadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter6.4
  12. CVE-2025-1291Gutenberg Blocks by Kadence Blocks <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon'6.4
  13. CVE-2024-12304Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link6.4
  14. CVE-2024-12581Kadence Blocks <= 3.2.53 - Authenticated (Admin+) Stored Cross-Site Scripting4.4
  15. CVE-2024-10785Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store