Junglewise Threat Intelligence

CVE-2026-18435: StellarWP Kadence Blocks stored XSS in toggleIcon attribute

CVE-2026-18435 · Severity: medium · CVSS 6.4 · Published 2026-08-01

Executive brief

Kadence Blocks is a popular WordPress plugin used to enhance the page-building experience. A security flaw allows users with basic contributor permissions to embed malicious scripts into website pages. When other users or administrators visit these pages, the scripts execute, potentially leading to unauthorized actions or data theft.

Technical details

The Kadence Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'toggleIcon' block attribute. Authenticated attackers with contributor-level access or higher can exploit this by injecting arbitrary web scripts into a page via the block editor. These scripts are stored on the server and execute in the browser of any user who views the affected page. The vulnerability is present in all versions up to and including 3.7.8. A patch has been released in subsequent versions to address the sanitization failure.

Affected products

  • stellarwp Kadence Blocks — Page Builder Toolkit for Gutenberg Editor up to, and including, 3.7.8

Timeline

  • 2026-08-01: disclosed
  • 2026-08-01: advisory

References

Related threats