Kadence WP Gutenberg Blocks with AI WordPress Plugin Unauthorized Post Publication Vulnerability

Vulnerability

A vulnerability exists in the 'Gutenberg Blocks with AI by Kadence WP – Page Builder Features' plugin for WordPress, affecting all versions up to and including 3.5.32. The issue arises from a misconfigured capability check in the 'process_pattern' REST API endpoint, which allows authenticated attackers with Contributor-level access or higher to create and publish posts of any type, including pages. This bypasses the standard WordPress review process, where contributions must be approved by an administrator.

Impact

Exploitation of this vulnerability allows for unauthorized post publication, bypassing the WordPress review workflow.

Remediation

Users can update to version 3.6.0 or a newer patched version to address this vulnerability.

Added: Jul 10, 2026, 5:49 AM
Updated: Jul 10, 2026, 5:49 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
0.6
exploitability
6.1
remediation
7.7
relevance
9.4
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.