Description
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.32. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
Problem types
Product status
* (semver)
Timeline
| 2026-02-16: | Vendor Notified |
| 2026-02-11: | Disclosed |
Credits
JohSka
References
www.wordfence.com/...-76e3-498b-80b8-c4befc545fc8?source=cve
vdp.patchstack.com/...ributor-post-publication-vulnerability
plugins.trac.wordpress.org/...gs/3.6.0&sfp_email=&sfph_mail=