Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.7.12.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS) that can execute arbitrary JavaScript in the context of site visitors
Action: Update Plugin
AI Analysis

Impact

The Gutenberg Blocks by Kadence Blocks plugin fails to sanitize user input before rendering it, allowing an attacker to embed malicious JavaScript into a block. The script is stored in the database and executed whenever a visitor loads a page containing that block, enabling session hijacking, credential theft, or site defacement. This is a classic stored XSS flaw identified as CWE‑79.

Affected Systems

All installations of the Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks plugin with versions up to and including 3.7.12 are affected. Versions 3.7.12.1 and newer contain the patch that neutralizes the vulnerability.

Risk and Exploitability

The CVSS score of 6.5 marks the flaw as moderate, indicating significant impact on confidentiality and integrity when exploited. No EPSS score is available and the vulnerability is not listed in CISA KEV, suggesting low observed exploitation activity to date. Exploitation requires the ability to create or edit a Gutenberg block via the WordPress block editor; once a malicious block is saved, the injected script runs automatically for every site visitor.

Generated by OpenCVE AI on October 8, 2026 at 18:04 UTC.

Remediation

Vendor Solution

Update the WordPress Gutenberg Blocks by Kadence Blocks plugin to the latest available version (at least 3.7.12.1).


OpenCVE Recommended Actions

  • Upgrade the Gutenberg Blocks by Kadence Blocks plugin to version 3.7.12.1 or newer.
  • Restrict editor access so that only trusted administrators can create or modify Gutenberg blocks.
  • If an upgrade is not immediately possible, remove or edit any existing blocks that may contain unsanitized content and prevent non‑admin users from editing blocks until the fix is applied.

Generated by OpenCVE AI on October 8, 2026 at 18:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.7.12.
Title WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.12 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-08T14:07:23.790Z

Reserved: 2026-10-06T00:18:26.658Z

Link: CVE-2026-105890

cve-icon Vulnrichment

Updated: 2026-10-08T14:07:19.105Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T13:17:13.930

Modified: 2026-10-08T17:24:11.230

Link: CVE-2026-105890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')