Kadence Blocks — Page Builder Toolkit For Gutenberg Editor
29 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Kadence Blocks — Page Builder Toolkit For Gutenberg Editor, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Kadence Blocks — Page Builder Toolkit For Gutenberg Editor CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 2 |
| 2024-12 | 1 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 3 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 3 |
| 2026-08 | 2 |
| 2026-09 | 0 |
Severity
How the 29 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High1
- Medium28
Latest CVEs
The 15 most recently published vulnerabilities affecting Kadence Blocks — Page Builder Toolkit For Gutenberg Editor.
- CVE-2026-18435Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute6.4
- CVE-2026-18062Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content6.4
- CVE-2026-15286Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication4.3
- CVE-2026-12902Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions4.3
- CVE-2026-12904Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter4.3
- CVE-2026-11357Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization4.3
- CVE-2026-2826Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media Upload4.3
- CVE-2026-2633Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload4.3
- CVE-2026-1857Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter4.3
- CVE-2026-2608Gutenberg Blocks by Kadence Blocks <= 3.5.32 - Missing Authorization4.3
- CVE-2025-5678Kadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter6.4
- CVE-2025-1291Gutenberg Blocks by Kadence Blocks <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon'6.4
- CVE-2024-12304Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link6.4
- CVE-2024-12581Kadence Blocks <= 3.2.53 - Authenticated (Admin+) Stored Cross-Site Scripting4.4
- CVE-2024-10785Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
Product grouping is registry-driven, with AI assist and human review. How it works