Extension WordPress

Vulnérabilités Kadence Blocks , Page Builder Toolkit for Gutenberg Editor, page 2

Cette page rassemble les failles publiées pour Kadence Blocks , Page Builder Toolkit for Gutenberg Editor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

35Vulnérabilités
1Critiques
35Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

35 fiches

CVE-2024-4057 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.36 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fileUrl attribute in versions up to, and including 3.2.36, due to insufficient input sanitization and…

Versions affectées

*-3.2.36

Correctif

3.2.37

Publication

14/05/2024

CVE-2024-4208 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 – Authenticated (Contributor+) Stored Cross-Site Scripting via Typer Effect

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the typer effect in the advanced heading widget in all versions up to, and including, 3.2.37…

Versions affectées

*-3.2.37

Correctif

3.2.38

Publication

14/05/2024

CVE-2024-3189 Moyenne · 5,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Testimonial', 'Progress Bar', 'Lottie Animations', 'Row Layout', 'Google Maps', and 'Advanced Gallery' blocks in all versions…

Versions affectées

*-3.2.37

Correctif

3.2.38

Publication

14/05/2024

CVE-2024-4209 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.36 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown timer in all versions up to, and including, 3.2.36 due to insufficient input sanitization…

Versions affectées

*-3.2.36

Correctif

3.2.37

Publication

10/05/2024

CVE-2024-4481 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks with AI by Kadence WP <= 3.2.36 – Authenticated (Contributor+) Stored Cross-Site Scripting via Block Link

The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the plugin's blocks in all versions up to, and including, 3.2.36 due to insufficient input sanitization…

Versions affectées

*-3.2.36

Correctif

3.2.37

Publication

09/05/2024

CVE-2024-2273 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.34 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 3.2.34 due to insufficient input sanitization and output escaping.…

Versions affectées

*-3.2.34

Correctif

3.2.35

Publication

01/05/2024

CVE-2023-6964 Élevée · 8,5
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.1.26 – Authenticated(Contributor+) Server-Side Request Forgery (SSRF)

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.26 via the 'kadence_import_get_new_connection_data' AJAX action. This makes it possible for authenticated…

Versions affectées

*-3.1.26

Correctif

3.2.12

Publication

09/04/2024

CVE-2024-2919 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.31 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via CountUp Widget

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CountUp Widget in all versions up to, and including, 3.2.31 due to insufficient input sanitization and output…

Versions affectées

*-3.2.31

Correctif

3.2.32

Publication

03/04/2024

CVE-2024-0598 Moyenne · 4,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks <= 3.2.17 – Authenticated(Editor+) Stored Cross-Site Scripting via Contact Form Message Settings

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form message settings in all versions up to and including 3.2.17 due to insufficient input sanitization…

Versions affectées

*-3.2.17

Correctif

3.2.18

Publication

02/04/2024

CVE-2024-24888 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks <= 3.2.25 – Authenticated (Author+) Server-Side Request Forgery

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.25. This makes it possible for authenticated attackers, with author-level access and…

Versions affectées

*-3.2.25

Correctif

3.2.26

Publication

29/03/2024

CVE-2024-23500 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.19 – Authenticated (Contributor+) Server-Side Request Forgery

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.19. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-3.2.19

Correctif

3.2.20

Publication

26/03/2024

CVE-2024-1999 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.25 – Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Widget

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget's anchor style parameter in all versions up to, and including, 3.2.25 due to insufficient input…

Versions affectées

*-3.2.25

Correctif

3.2.26

Publication

21/03/2024

CVE-2024-2509 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks <= 3.2.25 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Form widget in all versions up to, and including, 3.2.25 due to insufficient input sanitization…

Versions affectées

*-3.2.25

Correctif

3.2.26

Publication

15/03/2024

CVE-2024-1541 Moyenne · 6,4
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.23 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the htmlTag attribute in all versions up to, and including, 3.2.23 due to insufficient input sanitization and output…

Versions affectées

*-3.2.23

Correctif

3.2.24

Publication

01/03/2024

Vulnérabilité Critique · 9,8
Kadence Blocks , Page Builder Toolkit for Gutenberg Editor

Kadence Blocks <= 3.1.10 – Unauthenticated Arbitrary File Upload

The Kadence Blocks for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_fields function in versions up to, and including, 3.1.10. This makes it possible for unauthenticated attackers to upload arbitrary…

Versions affectées

[*, 3.1.11)

Correctif

3.1.11

Publication

09/08/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités