Impact
The vulnerability is a CWE‑79 (Cross‑Site Scripting) weakness that allows an authenticated user with contributor level access and above to embed unsanitized script text into the Inner Image Content field of Kadence Blocks’ Identity Block. When the block’s urlTransparent attribute is non‑empty, the build_html() routine fails to escape the content, resulting in a stored XSS payload that executes in the browser of any user who views the affected page. The flaw does not grant arbitrary code execution on the server but can be used to hijack sessions, deface pages, or deliver phishing content to site visitors.
Affected Systems
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor for WordPress, manufactured by stellarwp. Versions up to and including 3.7.8.1 are impacted. No other product versions are known to be affected.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated with contributor-level privileges, after which they can insert arbitrary script content that will run for every visitor to a page containing the vulnerable block. Although the attack vector is limited to authenticated users, once a malicious payload is stored it affects others, raising the potential impact to the confidentiality and integrity of site users.
OpenCVE Enrichment