CVE Database /
CVE-2026-12904
CVE · Medium
CVE-2026-12904 — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.8
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12904
|
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.8 |
Authorization Bypass Through User-Controlled Key |
Medium
4.3
|
< 3.7.8
|
3.7.8 |
2026-06-30 |
—
|
CVE-2026-12904
A WordPress plugin called Kadence Blocks is vulnerable to a security issue known as Insecure Direct Object Reference. Specifically, when an authenticated user with Contributor-level access or higher attempts to access or delete analysis records, the plugin checks their access rights based on the post ID they provide, but it doesn't verify whether that ID matches the actual path of the post being accessed. This allows attackers to potentially read or delete records belonging to other users by submitting the correct post ID and path.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings