Kadence Blocks WordPress Plugin Missing Capability Check Vulnerability

Vulnerability

A broken access control vulnerability has been identified in the Kadence Blocks – Page Builder Toolkit for Gutenberg Editor plugin for WordPress, affecting all versions through 3.5.32. The vulnerability arises from a missing capability check, allowing authenticated attackers with Contributor-level access and above to perform unauthorized actions.

Impact

Exploitation of this vulnerability could allow unauthorized actions to be performed by authenticated users with Contributor-level access or higher.

Remediation

Users of the Kadence Blocks WordPress plugin should update to version 3.6.0 or later to address this vulnerability.

Added: Feb 17, 2026, 12:24 PM
Updated: Feb 17, 2026, 12:24 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
3.1
exploitability
6.1
remediation
7.7
relevance
3.1
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.