CVE · Medium

CVE-2026-12904 — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12904 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.8 Authorization Bypass Through User-Controlled Key Medium 4.3 < 3.7.8 3.7.8 2026-06-30

CVE-2026-12904

A WordPress plugin called Kadence Blocks is vulnerable to a security issue known as Insecure Direct Object Reference. Specifically, when an authenticated user with Contributor-level access or higher attempts to access or delete analysis records, the plugin checks their access rights based on the post ID they provide, but it doesn't verify whether that ID matches the actual path of the post being accessed. This allows attackers to potentially read or delete records belonging to other users by submitting the correct post ID and path.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.