Impact
The vulnerability arises when the Kadence Blocks plugin fails to properly neutralize user input during page generation, permitting stored XSS. An attacker who can add or edit a block may inject arbitrary JavaScript that is persisted and executed in the browsers of any visitor to the affected site. This can lead to information disclosure, session hijacking, or defacement of the site.
Affected Systems
The flaw affects the Gutenberg Blocks by Kadence Blocks plugin from its earliest release up through version 3.7.11.1, installed on WordPress sites running the plugin. The affected vendors are Liquid Web and StellarWP, who provide and maintain the plugin.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity, and the flaw is not currently listed in CISA’s KEV catalog. The EPSS score is not available, so exploitation probability cannot be precisely quantified, but stored XSS is a well‑known attack vector that can be leveraged by any actor with permission to add or edit Gutenberg blocks. The most likely attack path involves an attacker crafting a malicious block that is stored in the database and rendered on page requests for all users.
OpenCVE Enrichment