Kadence WP Gutenberg Blocks with AI
cpe:2.3:a:kadencewp:gutenberg_blocks_with_ai:*:*:*:*:wordpress:*:*
- <= 3.5.32
A vulnerability exists in the 'Gutenberg Blocks with AI by Kadence WP – Page Builder Features' plugin for WordPress, affecting all versions up to and including 3.5.32. The issue arises from a misconfigured capability check in the 'process_pattern' REST API endpoint, which allows authenticated attackers with Contributor-level access or higher to create and publish posts of any type, including pages. This bypasses the standard WordPress review process, where contributions must be approved by an administrator.
Exploitation of this vulnerability allows for unauthorized post publication, bypassing the WordPress review workflow.
Users can update to version 3.6.0 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.