Extension WordPress

Vulnérabilités Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Cette page rassemble les failles publiées pour Kadence Blocks , Page Builder Toolkit for Gutenberg Editor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

35Vulnérabilités
1Critiques
35Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

35 fiches

CVE-2026-12904 Moyenne · 4,3
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Kadence Blocks <= 3.7.7 – Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter

The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 3.7.7. This is due to a mismatch between the object used for…

Versions affectées

*-3.7.7

Correctif

3.7.8

Publication

30/06/2026

CVE-2026-12902 Moyenne · 4,3
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Kadence Blocks <= 3.7.7 – Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions

The Kadence Blocks , Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.7. This is due to the plugin not properly verifying that a user…

Versions affectées

*-3.7.7

Correctif

3.7.8

Publication

30/06/2026

CVE-2026-11357 Moyenne · 4,3
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Kadence Blocks <= 3.7.5 – Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization

The Kadence Blocks , Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.5 via the editor_assets_variables. This makes it possible for authenticated attackers, with…

Versions affectées

*-3.7.5

Correctif

3.7.6

Publication

17/06/2026

CVE-2026-2826 Moyenne · 4,3
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Kadence Blocks , Page Builder Toolkit for Gutenberg Editor <= 3.6.3 – Missing Authorization to Authenticated (Contributor+) Media Upload

The Kadence Blocks , Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user…

Versions affectées

*-3.6.3

Correctif

3.6.4

Publication

03/04/2026

CVE-2026-2633 Moyenne · 4,3
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks with AI by Kadence WP <= 3.6.1 – Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload

The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.1. This is due to a missing capability check in the `process_image_data_ajax_callback()` function which handles…

Versions affectées

*-3.6.1

Correctif

3.6.2

Publication

17/02/2026

CVE-2026-1857 Moyenne · 4,3
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks with AI by Kadence WP <= 3.6.1 – Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter

The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.6.1. This is due to insufficient validation of the `endpoint` parameter in the `get_items()`…

Versions affectées

*-3.6.1

Correctif

3.6.2

Publication

17/02/2026

CVE-2026-15286 Moyenne · 4,3
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 – Incorrect Authorization to Authenticated (Contributor+) Post Publication

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post publication in all versions up to, and including, 3.5.32 due to a misconfigured capability check on the 'get_items_permission_check'…

Versions affectées

*-3.5.32

Correctif

3.6.0

Publication

10/02/2026

CVE-2025-5678 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Kadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 – Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘redirectURL’ parameter in all versions up to, and including, 3.5.10 due to insufficient input sanitization…

Versions affectées

*-3.5.10

Correctif

3.5.11

Publication

08/07/2025

CVE-2025-1291 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks <= 3.4.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon'

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icon’ parameter in all versions up to, and including, 3.4.9 due to insufficient input sanitization…

Versions affectées

*-3.4.9

Correctif

3.4.10

Publication

28/02/2025

CVE-2024-12304 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.4.2 – Authenticated (contributor+) Stored Cross-Site Scripting via Button Link

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via button block link in all versions up to, and including, 3.4.2 due to insufficient input sanitization…

Versions affectées

*-3.4.2

Correctif

3.4.3

Publication

10/01/2025

CVE-2024-10637 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Kadence Blocks <= 3.2.53 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.2.53 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-3.2.53

Correctif

3.2.54

Publication

21/11/2024

CVE-2024-12581 Moyenne · 4,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Kadence Blocks <= 3.2.53 – Authenticated (Admin+) Stored Cross-Site Scripting

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.53 due to insufficient input sanitization and…

Versions affectées

*-3.2.53

Correctif

3.2.54

Publication

21/11/2024

CVE-2024-10785 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 3.3.3 due to insufficient input sanitization…

Versions affectées

*-3.3.3

Correctif

3.3.4

Publication

20/11/2024

CVE-2024-9655 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Widget

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon widget in all versions up to, and including, 6.6.2 due to insufficient input…

Versions affectées

*-3.3.1

Correctif

3.3.2

Publication

31/10/2024

CVE-2024-6884 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.38 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Block in all versions up to, and including, 3.2.38 due to insufficient input sanitization…

Versions affectées

*-3.2.28

Correctif

3.2.39

Publication

18/07/2024

CVE-2024-5819 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.45 – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data Attributes

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data attributes in all versions up to, and including, 3.2.45 due to insufficient input…

Versions affectées

*-3.2.45

Correctif

3.2.46

Publication

28/06/2024

CVE-2024-5289 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.42 – Authenticated (Contributor+) Stored Cross-Site Scripting in Google Maps Widget

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget parameters in all versions up to, and including, 3.2.42 due to insufficient…

Versions affectées

*-3.2.42

Correctif

3.2.43

Publication

26/06/2024

CVE-2024-4863 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.38 – Authenticated (Contributor+) Stored Cross-Site Scripting via titleFont Parameter

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘titleFont’ parameter in all versions up to, and including, 3.2.38 due to insufficient input sanitization…

Versions affectées

*-3.2.38

Correctif

3.2.39

Publication

13/06/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités