Stored Cross-Site Scripting in Kadence Blocks Plugin for WordPress
CVE-2026-18062

6.4MEDIUM

What is CVE-2026-18062?

The Kadence Blocks plugin for WordPress contains a stored cross-site scripting vulnerability that allows authenticated attackers with contributor-level access or higher to inject malicious scripts into pages. This occurs due to insufficient input sanitization and output escaping within the Identity Block Inner Image Content functionality. Specifically, this vulnerability is triggered when the block's urlTransparent attribute is set to a non-empty value, enabling the execution of arbitrary web scripts whenever users access the modified pages.

Affected Version(s)

Kadence Blocks β€” Page Builder Toolkit for Gutenberg Editor 0 <= 3.7.8.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17y
.