Description
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
Published: 2026-08-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Gutenberg Blocks by Kadence Blocks plugin allows the disclosure of contributor credentials or other sensitive information. The vulnerability is documented as a CWE‑201 information exposure weakness, meaning that data that should be protected can be read by an attacker. The flaw does not provide a privilege escalation or arbitrary code execution path, but the leaked data could be used for further attacks such as credential compromise or phishing.

Affected Systems

WordPress installations that have the Kadence Blocks plugin from Nexcess running any version up to and including 3.7.8 are impacted. The problem is confined to the plugin itself and does not affect the core WordPress codebase.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and the available information shows no published exploit or evidence of targeted attacks. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely need to locate a site with a vulnerable plugin version and then interact with the plugin’s contributor feature to exfiltrate data. The overall risk is moderate, but the exposure of sensitive information can enable more damaging secondary attacks.

Generated by OpenCVE AI on August 6, 2026 at 16:04 UTC.

Remediation

Vendor Solution

Update the WordPress Gutenberg Blocks by Kadence Blocks Plugin to the latest available version (at least 3.7.8.1).


OpenCVE Recommended Actions

  • Update the WordPress Gutenberg Blocks by Kadence Blocks Plugin to version 3.7.8.1 or later.
  • If the plugin must remain at an older version for compatibility, disable any contributor-related functionality that exposes sensitive data.
  • Clear any cached or backup files that may still contain the sensitive information after updating, and review the site’s logs for abnormal access patterns.

Generated by OpenCVE AI on August 6, 2026 at 16:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Nexcess
Nexcess gutenberg Blocks By Kadence Blocks
Wordpress
Wordpress wordpress
Vendors & Products Nexcess
Nexcess gutenberg Blocks By Kadence Blocks
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
Title WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Nexcess Gutenberg Blocks By Kadence Blocks
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T15:05:54.728Z

Reserved: 2026-07-27T14:01:09.905Z

Link: CVE-2026-66696

cve-icon Vulnrichment

Updated: 2026-08-06T15:04:17.487Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T15:17:22.730

Modified: 2026-08-12T20:59:00.027

Link: CVE-2026-66696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:59:35Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data