Kadence Blocks
cpe:2.3:a:kadencewp:gutenberg_blocks_with_ai:*:*:*:*:wordpress:*:*
- <= 3.5.32
A broken access control vulnerability has been identified in the Kadence Blocks – Page Builder Toolkit for Gutenberg Editor plugin for WordPress, affecting all versions through 3.5.32. The vulnerability arises from a missing capability check, allowing authenticated attackers with Contributor-level access and above to perform unauthorized actions.
Exploitation of this vulnerability could allow unauthorized actions to be performed by authenticated users with Contributor-level access or higher.
Users of the Kadence Blocks WordPress plugin should update to version 3.6.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.