Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks
CVE-2026-66696

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 August 2026

What is CVE-2026-66696?

The Gutenberg Blocks by Kadence Blocks plugin has a vulnerability that allows unauthorized access to sensitive data. This issue affects versions up to 3.7.8, potentially compromising the integrity of user data. It is crucial for users and administrators of affected versions to apply security updates promptly to mitigate risks associated with this exposure. Regular security practices and monitoring can help safeguard against such vulnerabilities.

Affected Version(s)

Gutenberg Blocks by Kadence Blocks <= 3.7.8

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdullah Kareem "cyberkareem" | Patchstack Bug Bounty Program
.