Impact
A flaw in the Gutenberg Blocks by Kadence Blocks plugin allows the disclosure of contributor credentials or other sensitive information. The vulnerability is documented as a CWE‑201 information exposure weakness, meaning that data that should be protected can be read by an attacker. The flaw does not provide a privilege escalation or arbitrary code execution path, but the leaked data could be used for further attacks such as credential compromise or phishing.
Affected Systems
WordPress installations that have the Kadence Blocks plugin from Nexcess running any version up to and including 3.7.8 are impacted. The problem is confined to the plugin itself and does not affect the core WordPress codebase.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the available information shows no published exploit or evidence of targeted attacks. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely need to locate a site with a vulnerable plugin version and then interact with the plugin’s contributor feature to exfiltrate data. The overall risk is moderate, but the exposure of sensitive information can enable more damaging secondary attacks.
OpenCVE Enrichment