Extension WordPress
Vulnérabilités Kadence Blocks , Page Builder Toolkit for Gutenberg Editor, page 2
Cette page rassemble les failles publiées pour Kadence Blocks , Page Builder Toolkit for Gutenberg Editor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Kadence Blocks , Page Builder Toolkit for Gutenberg Editor
35 fiches
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.36 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the fileUrl attribute in versions up to, and including 3.2.36, due to insufficient input sanitization and…
*-3.2.36
3.2.37
14/05/2024
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 – Authenticated (Contributor+) Stored Cross-Site Scripting via Typer Effect
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the typer effect in the advanced heading widget in all versions up to, and including, 3.2.37…
*-3.2.37
3.2.38
14/05/2024
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Testimonial', 'Progress Bar', 'Lottie Animations', 'Row Layout', 'Google Maps', and 'Advanced Gallery' blocks in all versions…
*-3.2.37
3.2.38
14/05/2024
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.36 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown timer in all versions up to, and including, 3.2.36 due to insufficient input sanitization…
*-3.2.36
3.2.37
10/05/2024
Gutenberg Blocks with AI by Kadence WP <= 3.2.36 – Authenticated (Contributor+) Stored Cross-Site Scripting via Block Link
The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the plugin's blocks in all versions up to, and including, 3.2.36 due to insufficient input sanitization…
*-3.2.36
3.2.37
09/05/2024
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.34 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 3.2.34 due to insufficient input sanitization and output escaping.…
*-3.2.34
3.2.35
01/05/2024
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.1.26 – Authenticated(Contributor+) Server-Side Request Forgery (SSRF)
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.26 via the 'kadence_import_get_new_connection_data' AJAX action. This makes it possible for authenticated…
*-3.1.26
3.2.12
09/04/2024
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.31 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via CountUp Widget
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CountUp Widget in all versions up to, and including, 3.2.31 due to insufficient input sanitization and output…
*-3.2.31
3.2.32
03/04/2024
Gutenberg Blocks by Kadence Blocks <= 3.2.17 – Authenticated(Editor+) Stored Cross-Site Scripting via Contact Form Message Settings
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form message settings in all versions up to and including 3.2.17 due to insufficient input sanitization…
*-3.2.17
3.2.18
02/04/2024
Gutenberg Blocks by Kadence Blocks <= 3.2.25 – Authenticated (Author+) Server-Side Request Forgery
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.25. This makes it possible for authenticated attackers, with author-level access and…
*-3.2.25
3.2.26
29/03/2024
Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.19 – Authenticated (Contributor+) Server-Side Request Forgery
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.19. This makes it possible for authenticated attackers, with contributor-level…
*-3.2.19
3.2.20
26/03/2024
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.25 – Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Widget
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget's anchor style parameter in all versions up to, and including, 3.2.25 due to insufficient input…
*-3.2.25
3.2.26
21/03/2024
Gutenberg Blocks by Kadence Blocks <= 3.2.25 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Form widget in all versions up to, and including, 3.2.25 due to insufficient input sanitization…
*-3.2.25
3.2.26
15/03/2024
Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.23 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the htmlTag attribute in all versions up to, and including, 3.2.23 due to insufficient input sanitization and output…
*-3.2.23
3.2.24
01/03/2024
Kadence Blocks <= 3.1.10 – Unauthenticated Arbitrary File Upload
The Kadence Blocks for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_fields function in versions up to, and including, 3.1.10. This makes it possible for unauthenticated attackers to upload arbitrary…
[*, 3.1.11)
3.1.11
09/08/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.