Stored Cross-Site Scripting in Kadence Blocks Plugin for WordPress
CVE-2026-18062
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2026
What is CVE-2026-18062?
The Kadence Blocks plugin for WordPress contains a stored cross-site scripting vulnerability that allows authenticated attackers with contributor-level access or higher to inject malicious scripts into pages. This occurs due to insufficient input sanitization and output escaping within the Identity Block Inner Image Content functionality. Specifically, this vulnerability is triggered when the block's urlTransparent attribute is set to a non-empty value, enabling the execution of arbitrary web scripts whenever users access the modified pages.
Affected Version(s)
Kadence Blocks β Page Builder Toolkit for Gutenberg Editor 0 <= 3.7.8.1