Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

Vulnerabilities 34Slug kadence-blocksLatest version 3.7.1WordPress.org →

Minimum safe version

3.6.4

Update to 3.6.4 or later to address 34 fixable vulnerabilities

Latest available3.7.1
N/A
2026-02-10< 3.6.0

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication

N/A
2026-02-11< 3.6.0

Gutenberg Blocks by Kadence Blocks <= 3.5.32 - Missing Authorization

N/A
2026-02-17< 3.6.2

Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter

N/A
2026-02-17< 3.6.2

Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload

N/A
2026-04-03< 3.6.4

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media Upload

Medium 6.4
2025-07-09< 3.5.11

Kadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter

Medium 6.4
2025-03-01< 3.4.10

Gutenberg Blocks by Kadence Blocks <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon'

Medium 5.4
2024-07-01< 3.2.46

WordPress Gutenberg Blocks by Kadence Blocks Plugin <= 3.2.45 is vulnerable to Cross Site Scripting (XSS)

N/A
2023-08-09< 3.1.11

WordPress Gutenberg Blocks by Kadence Blocks Plugin <= 3.1.10 is vulnerable to Arbitrary File Upload

N/A
2023-08-09< 3.1.11

Kadence Blocks <= 3.1.10 - Unauthenticated Arbitrary File Upload