Cross-Site Scripting
24 records64.9%First: 2024. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 37 vulnerability records associated with Kadence Blocks — Page Builder Toolkit for Gutenberg Editor, published between 2023 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2023 | 1 | |
| 2024 | 22 | |
| 2025 | 4 | |
| 2026 | 10 |
| Severity | Records | Share |
|---|---|---|
| Critical | 1 | 2.7% |
| High | 1 | 2.7% |
| Medium | 35 | 94.6% |
First: 2024. Latest: 2026.
First: 2025. Latest: 2026.
First: 2024. Latest: 2026.
First: 2023. Latest: 2023.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.7.8.23.7.8.13.7.83.7.63.6.43.6.23.6.03.5.113.4.103.3.23.4.33.2.543.3.43.2.393.2.463.2.433.2.383.2.373.2.353.2.123.2.323.2.183.2.263.2.203.2.243.1.11Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.7.8.1 | Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content | July 31, 2026 | 3.7.8.2 | Medium |
*-3.7.8 | Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute | July 31, 2026 | 3.7.8.1 | Medium |
*-3.7.7 | Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter | June 30, 2026 | 3.7.8 | Medium |
*-3.7.7 | Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions | June 30, 2026 | 3.7.8 | Medium |
*-3.7.5 | Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization | June 17, 2026 | 3.7.6 | Medium |
*-3.6.3 | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media Upload | April 3, 2026 | 3.6.4 | Medium |
*-3.6.1 | Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload | February 17, 2026 | 3.6.2 | Medium |
*-3.6.1 | Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter | February 17, 2026 | 3.6.2 | Medium |
*-3.5.32 | Gutenberg Blocks by Kadence Blocks <= 3.5.32 - Missing Authorization | February 11, 2026 | 3.6.0 | Medium |
*-3.5.32 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication | February 10, 2026 | 3.6.0 | Medium |
*-3.5.10 | Kadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter | July 8, 2025 | 3.5.11 | Medium |
*-3.4.9 | Gutenberg Blocks by Kadence Blocks <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' | February 28, 2025 | 3.4.10 | Medium |
*-3.3.1 | Gutenberg Blocks by Kadence Blocks <= 3.3.1 - Missing Authorization | January 24, 2025 | 3.3.2 | Medium |
*-3.4.2 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link | January 10, 2025 | 3.4.3 | Medium |
*-3.2.53 | Kadence Blocks <= 3.2.53 - Authenticated (Contributor+) Stored Cross-Site Scripting | November 21, 2024 | 3.2.54 | Medium |
*-3.2.53 | Kadence Blocks <= 3.2.53 - Authenticated (Admin+) Stored Cross-Site Scripting | November 21, 2024 | 3.2.54 | Medium |
*-3.3.3 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | November 20, 2024 | 3.3.4 | Medium |
*-3.3.1 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Widget | October 31, 2024 | 3.3.2 | Medium |
*-3.2.28 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown | July 18, 2024 | 3.2.39 | Medium |
*-3.2.45 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.45 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data Attributes | June 28, 2024 | 3.2.46 | Medium |
*-3.2.42 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.42 - Authenticated (Contributor+) Stored Cross-Site Scripting in Google Maps Widget | June 26, 2024 | 3.2.43 | Medium |
*-3.2.38 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via titleFont Parameter | June 13, 2024 | 3.2.39 | Medium |
*-3.2.36 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting | May 14, 2024 | 3.2.37 | Medium |
*-3.2.37 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typer Effect | May 14, 2024 | 3.2.38 | Medium |
*-3.2.37 | Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting | May 14, 2024 | 3.2.38 | Medium |
Selected source records
Published: July 31, 2026
Published: July 31, 2026
Published: June 30, 2026
Published: June 30, 2026
Published: June 17, 2026
Published: April 3, 2026
Published: February 17, 2026
Published: February 17, 2026
Published: August 9, 2023
Published: April 9, 2024
Published: July 18, 2024
Published: March 29, 2024
Published: June 13, 2024
Published: November 20, 2024
Published: July 31, 2026
Published: July 31, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.