Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
Minimum safe version
3.6.4
Update to 3.6.4 or later to address 34 fixable vulnerabilities
Gutenberg Blocks by Kadence Blocks <= 3.5.32 - Missing Authorization
Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter
Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media Upload
Kadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter
Gutenberg Blocks by Kadence Blocks <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon'
CVE-2025-24753
CVE-2024-12304
CVE-2024-12581
CVE-2024-10637
CVE-2024-10785
CVE-2024-9655
CVE-2024-6884
WordPress Gutenberg Blocks by Kadence Blocks Plugin <= 3.2.45 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-5289
CVE-2024-4863
CVE-2024-4057
CVE-2024-4208
CVE-2024-3189
CVE-2024-4209
CVE-2024-4481
CVE-2024-2273
CVE-2023-6964
CVE-2024-2509
CVE-2024-2919
CVE-2024-0598
CVE-2024-24888
CVE-2024-23500
CVE-2024-2866
CVE-2024-1999
CVE-2024-1541
WordPress Gutenberg Blocks by Kadence Blocks Plugin <= 3.1.10 is vulnerable to Arbitrary File Upload
Kadence Blocks <= 3.1.10 - Unauthenticated Arbitrary File Upload