Junglewise Threat Intelligence

CVE-2026-66696: Kadence Blocks sensitive data exposure in Gutenberg editor

CVE-2026-66696 · Severity: medium · CVSS 4.3 · Published 2026-08-06

Executive brief

Kadence Blocks is a popular WordPress plugin providing page building and content editing capabilities through the Gutenberg editor. A vulnerability in versions 3.7.8 and earlier allows contributors with basic editing privileges to access and expose sensitive data (such as passwords, email addresses, or payment details) that should be restricted from their role level. This could lead to unauthorized disclosure of confidential information.

Technical details

The vulnerability is classified as sensitive data exposure in the Kadence Blocks plugin for WordPress Gutenberg. A contributor-level user (a role with limited privileges intended for content submission only) can access and exfiltrate sensitive data that should be restricted by role-based access controls. The attack requires network access and valid plugin installation but no admin authentication—only basic contributor credentials are needed. The vulnerability was patched in version 3.7.8.1 and later. The root cause appears to stem from inadequate permission checks on sensitive data retrieval or display functions within the block editor interface.

Affected products

  • Liquid Web / StellarWP Kadence Blocks 3.7.8 and earlier

Timeline

  • 2026-07-29: disclosed
  • 2026-08-06: patched: Fixed in version 3.7.8.1

References