Stored Cross-Site Scripting Vulnerability in Kadence Blocks Page Builder Toolkit for WordPress
CVE-2026-104762
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-104762?
The Kadence Blocks plugin, a popular page builder toolkit for the Gutenberg Editor in WordPress, is susceptible to stored cross-site scripting (XSS) attacks due to inadequate input sanitization and output escaping. This vulnerability affects all versions up to and including 3.7.12, enabling authenticated attackers with author-level access or higher to inject malicious web scripts. These scripts could execute when unsuspecting users visit compromised pages. Notably, this encoding bypass occurs only when the 'Load Google Fonts Locally' option is activated, which is not set as the default configuration.
Affected Version(s)
Kadence Blocks β Page Builder Toolkit for Gutenberg Editor 0 <= 3.7.12