Stored Cross-Site Scripting Vulnerability in Kadence Blocks Page Builder Toolkit for WordPress
CVE-2026-104762

6.4MEDIUM

What is CVE-2026-104762?

The Kadence Blocks plugin, a popular page builder toolkit for the Gutenberg Editor in WordPress, is susceptible to stored cross-site scripting (XSS) attacks due to inadequate input sanitization and output escaping. This vulnerability affects all versions up to and including 3.7.12, enabling authenticated attackers with author-level access or higher to inject malicious web scripts. These scripts could execute when unsuspecting users visit compromised pages. Notably, this encoding bypass occurs only when the 'Load Google Fonts Locally' option is activated, which is not set as the default configuration.

Affected Version(s)

Kadence Blocks β€” Page Builder Toolkit for Gutenberg Editor 0 <= 3.7.12

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.