PLUGIN SECURITY

Is Kadence Blocks safe?

20+ Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.

What this plugin does

  • Slug: kadence-blocks
  • Author: Nexcess
  • 600000+ active installs
  • 96/100 rating (330 reviews on wordpress.org)
  • 40398469 all-time downloads
  • On WordPress.org since 2018-08-19

blockseditorgutenberggutenberg blockspage builder

Maintenance status

  • Latest known version: 3.7.9
  • Last updated: 2026-08-12 4:59pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

38 known CVEs on file for Kadence Blocks.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-18435 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.8.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.7.8.1 3.7.8.1 2026-07-31 ✓ fixed in latest
CVE-2026-18062 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.8.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.7.8.2 3.7.8.2 2026-07-31 ✓ fixed in latest
CVE-2026-66696 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.8.1 Insertion of Sensitive Information Into Sent Data Medium 4.3 < 3.7.8.1 3.7.8.1 2026-07-29 ✓ fixed in latest
CVE-2026-12902 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.8 Missing Authorization Medium 4.3 < 3.7.8 3.7.8 2026-06-30 ✓ fixed in latest
CVE-2026-12904 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.8 Authorization Bypass Through User-Controlled Key Medium 4.3 < 3.7.8 3.7.8 2026-06-30 ✓ fixed in latest
CVE-2026-11357 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.6 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 3.7.6 3.7.6 2026-06-17 ✓ fixed in latest
CVE-2026-15286 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.6.0 Incorrect Authorization Medium 4.3 < 3.6.0 3.6.0 2026-02-10 ✓ fixed in latest
CVE-2025-24753 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.3.2 Missing Authorization Medium 4.3 < 3.3.2 3.3.2 2025-01-24 ✓ fixed in latest
+ 39 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-12304 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.4.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.4.3 3.4.3 2025-01-10 ✓ fixed in latest
CVE-2024-10637 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.54 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.54 3.2.54 2024-11-21 ✓ fixed in latest
CVE-2024-12581 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.54 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.4 < 3.2.54 3.2.54 2024-11-21 ✓ fixed in latest
CVE-2024-10785 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.3.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.3.4 3.3.4 2024-11-20 ✓ fixed in latest
CVE-2024-9655 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.3.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.3.2 3.3.2 2024-10-31 ✓ fixed in latest
CVE-2024-6884 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.39 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.53 3.2.53 2024-07-18 ✓ fixed in latest
CVE-2024-5819 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.46 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.46 3.2.46 2024-06-28 ✓ fixed in latest
CVE-2024-5289 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.43 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.43 3.2.43 2024-06-26 ✓ fixed in latest
CVE-2024-4863 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.39 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.39 3.2.39 2024-06-13 ✓ fixed in latest
CVE-2024-3189 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.38 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.38 3.2.38 2024-05-14 ✓ fixed in latest
CVE-2024-4208 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.38 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.38 3.2.38 2024-05-14 ✓ fixed in latest
CVE-2024-4057 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.37 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.2.37 3.2.37 2024-05-14 ✓ fixed in latest
CVE-2024-4209 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.37 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.37 3.2.37 2024-05-10 ✓ fixed in latest
CVE-2024-4481 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.37 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.37 3.2.37 2024-05-09 ✓ fixed in latest
CVE-2024-2273 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.35 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.35 3.2.35 2024-05-01 ✓ fixed in latest
CVE-2023-6964 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.12 Server-Side Request Forgery (SSRF) Medium 6.4 < 3.2.12 3.2.12 2024-04-09 ✓ fixed in latest
CVE-2024-2509 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.26 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.2.26 3.2.26 2024-04-05 ✓ fixed in latest
CVE-2024-2919 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.32 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.32 3.2.32 2024-04-03 ✓ fixed in latest
CVE-2024-0598 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.18 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.2.18 3.2.18 2024-04-02 ✓ fixed in latest
CVE-2024-24888 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.26 Server-Side Request Forgery (SSRF) Medium 6.4 < 3.2.26 3.2.26 2024-03-29 ✓ fixed in latest
CVE-2024-23500 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.20 Server-Side Request Forgery (SSRF) High 7.7 < 3.2.20 3.2.20 2024-03-26 ✓ fixed in latest
CVE-2024-1999 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.26 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.26 3.2.26 2024-03-21 ✓ fixed in latest
CVE-2024-2866 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.26 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 3.2.26 3.2.26 2024-03-15 ✓ fixed in latest
CVE-2024-1541 Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.2.24 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.24 3.2.24 2024-03-01 ✓ fixed in latest
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.1.11 Unknown < 3.1.11 3.1.11 2023-08-09 ✓ fixed in latest
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.1.11 Unknown < 3.1.11 3.1.11 2023-08-09 ✓ fixed in latest
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.4.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.4.10 3.4.10 0000-00-00 ✓ fixed in latest
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.5.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.5.11 3.5.11 0000-00-00 ✓ fixed in latest
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.6.4 Unknown < 3.6.4 3.6.4 0000-00-00 ✓ fixed in latest
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.6.2 Unknown < 3.6.2 3.6.2 0000-00-00 ✓ fixed in latest
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.6.2 Unknown < 3.6.2 3.6.2 0000-00-00 ✓ fixed in latest
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.6.0 Unknown < 3.6.0 3.6.0 0000-00-00 ✓ fixed in latest
CVE-2025-1291 Gutenberg Blocks by Kadence Blocks < 3.4.10 - Contributor+ Stored XSS Unknown < 3.4.10 3.4.10 ✓ fixed in latest
CVE-2025-5678 Kadence Blocks – Gutenberg Blocks for Page Builder Features < 3.5.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter Unknown < 3.5.11 3.5.11 ✓ fixed in latest
CVE-2026-2608 Gutenberg Blocks by Kadence Blocks < 3.6.0 - Missing Authorization Unknown < 3.6.0 3.6.0 ✓ fixed in latest
CVE-2026-1857 Gutenberg Blocks with AI by Kadence WP < 3.6.2 - Contributor+ SSRF Unknown < 3.6.2 3.6.2 ✓ fixed in latest
CVE-2026-2633 Gutenberg Blocks with AI by Kadence WP < 3.6.2 - Contributor+ Unauthorized Media Upload Unknown < 3.6.2 3.6.2 ✓ fixed in latest
CVE-2026-2826 Kadence Blocks < 3.6.4 - Contributor+ Media Upload Unknown < 3.6.4 3.6.4 ✓ fixed in latest
Page Builder Features < 3.6.0 - Contributor+ Post Publication Unknown < 3.6.0 3.6.0 ✓ fixed in latest

How to fix it

Keep Kadence Blocks updated — 3.7.9 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.