Impact
The Gutenberg Blocks by Kadence Blocks plugin fails to sanitize user input before rendering it, allowing an attacker to embed malicious JavaScript into a block. The script is stored in the database and executed whenever a visitor loads a page containing that block, enabling session hijacking, credential theft, or site defacement. This is a classic stored XSS flaw identified as CWE‑79.
Affected Systems
All installations of the Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks plugin with versions up to and including 3.7.12 are affected. Versions 3.7.12.1 and newer contain the patch that neutralizes the vulnerability.
Risk and Exploitability
The CVSS score of 6.5 marks the flaw as moderate, indicating significant impact on confidentiality and integrity when exploited. No EPSS score is available and the vulnerability is not listed in CISA KEV, suggesting low observed exploitation activity to date. Exploitation requires the ability to create or edit a Gutenberg block via the WordPress block editor; once a malicious block is saved, the injected script runs automatically for every site visitor.
OpenCVE Enrichment