Cross-site Scripting Vulnerability in Liquid Web's Gutenberg Blocks by Kadence Blocks
CVE-2026-103354
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 October 2026
What is CVE-2026-103354?
The Gutenberg Blocks by Kadence Blocks, a product of Liquid Web, is susceptible to a Cross-site Scripting (XSS) vulnerability due to improper neutralization of user inputs during web page generation. This flaw can lead to the execution of malicious scripts in the context of users' browsers, posing a significant security risk for users of versions up to and including 3.7.11.1. Attackers could exploit this vulnerability to store malicious payloads, which, upon triggered by unsuspecting users, could compromise their data and web integrity.
Affected Version(s)
Gutenberg Blocks by Kadence Blocks 0 <= 3.7.11.1