{"schema_version":1,"title":"StellarWP Kadence Blocks vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 7 vulnerabilities in StellarWP Kadence Blocks: 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-66696, was published on 6 August 2026.","url":"https://junglewise.ai/threats/technologies/kadence-blocks","json_url":"https://junglewise.ai/threats/technologies/kadence-blocks.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/kadence-blocks","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":7,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":5,"last_365_days":7},"latest":[{"cve":"CVE-2026-66696","cvss":4.3,"epss":0.003,"slug":"cve-2026-66696-kadence-blocks-sensitive-data-exposure-in-gutenberg-editor","title":"Kadence Blocks sensitive data exposure in Gutenberg editor","severity":"medium","exploited":false,"published_at":"2026-08-06T15:17:22.73+00:00","url":"https://junglewise.ai/threats/cve-2026-66696-kadence-blocks-sensitive-data-exposure-in-gutenberg-editor"},{"cve":"CVE-2026-18435","cvss":6.4,"slug":"cve-2026-18435-stellarwp-kadence-blocks-stored-xss-in-toggleicon-attribute","title":"StellarWP Kadence Blocks stored XSS in toggleIcon attribute","severity":"medium","exploited":false,"published_at":"2026-08-01T09:17:02.383+00:00","url":"https://junglewise.ai/threats/cve-2026-18435-stellarwp-kadence-blocks-stored-xss-in-toggleicon-attribute"},{"cve":"CVE-2026-18062","cvss":6.4,"slug":"cve-2026-18062-stellarwp-kadence-blocks-stored-xss-in-identity-block","title":"StellarWP Kadence Blocks Stored XSS in Identity Block","severity":"medium","exploited":false,"published_at":"2026-08-01T09:17:02.1+00:00","url":"https://junglewise.ai/threats/cve-2026-18062-stellarwp-kadence-blocks-stored-xss-in-identity-block"},{"cve":"CVE-2026-15286","cvss":4.3,"slug":"cve-2026-15286-kadence-wp-gutenberg-blocks-unauthorized-post-publication-in-rest","title":"Kadence WP Gutenberg Blocks unauthorized post publication in REST API","severity":"medium","exploited":false,"published_at":"2026-07-10T05:16:31.343+00:00","url":"https://junglewise.ai/threats/cve-2026-15286-kadence-wp-gutenberg-blocks-unauthorized-post-publication-in-rest"},{"cve":"CVE-2026-12902","cvss":4.3,"slug":"cve-2026-12902-stellarwp-kadence-blocks-authorization-bypass-in-prebuilt-library","title":"StellarWP Kadence Blocks authorization bypass in prebuilt library","severity":"medium","exploited":false,"published_at":"2026-07-01T05:16:17.757+00:00","url":"https://junglewise.ai/threats/cve-2026-12902-stellarwp-kadence-blocks-authorization-bypass-in-prebuilt-library"},{"cve":"CVE-2026-11357","cvss":4.3,"epss":0.0024,"slug":"cve-2026-11357-stellarwp-kadence-blocks-sensitive-information-exposure-in-editor","title":"StellarWP Kadence Blocks sensitive information exposure in editor_assets_variables","severity":"medium","exploited":false,"published_at":"2026-06-18T06:16:56.703+00:00","url":"https://junglewise.ai/threats/cve-2026-11357-stellarwp-kadence-blocks-sensitive-information-exposure-in-editor"},{"cve":"CVE-2026-2826","cvss":4.3,"epss":0.003,"slug":"cve-2026-2826-stellarwp-kadence-blocks-authorization-bypass-in-process-pattern","title":"StellarWP Kadence Blocks authorization bypass in process_pattern REST API","severity":"medium","exploited":false,"published_at":"2026-04-04T09:16:20.167+00:00","url":"https://junglewise.ai/threats/cve-2026-2826-stellarwp-kadence-blocks-authorization-bypass-in-process-pattern"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"StellarWP GiveWP","slug":"givewp","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/givewp"},{"name":"StellarWP The Events Calendar","slug":"the-events-calendar","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/the-events-calendar"},{"name":"StellarWP Event Tickets","slug":"event-tickets","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/event-tickets"}],"technology":{"hub":true,"name":"StellarWP Kadence Blocks","slug":"kadence-blocks","vendor":{"name":"StellarWP","slug":"stellarwp","url":"https://junglewise.ai/threats/vendors/stellarwp"},"aliases":["kadence-blocks-page-builder-toolkit-for-gutenberg-editor"],"category":"library","homepage":"https://www.kadencewp.com/kadence-blocks/","repo_url":"https://github.com/kadencewp/kadence-blocks","description":"A collection of custom blocks for the WordPress Gutenberg editor used to extend page building capabilities.","url":"https://junglewise.ai/threats/technologies/kadence-blocks"},"most_severe":[{"cve":"CVE-2026-18435","cvss":6.4,"slug":"cve-2026-18435-stellarwp-kadence-blocks-stored-xss-in-toggleicon-attribute","title":"StellarWP Kadence Blocks stored XSS in toggleIcon attribute","severity":"medium","exploited":false,"published_at":"2026-08-01T09:17:02.383+00:00","url":"https://junglewise.ai/threats/cve-2026-18435-stellarwp-kadence-blocks-stored-xss-in-toggleicon-attribute"},{"cve":"CVE-2026-18062","cvss":6.4,"slug":"cve-2026-18062-stellarwp-kadence-blocks-stored-xss-in-identity-block","title":"StellarWP Kadence Blocks Stored XSS in Identity Block","severity":"medium","exploited":false,"published_at":"2026-08-01T09:17:02.1+00:00","url":"https://junglewise.ai/threats/cve-2026-18062-stellarwp-kadence-blocks-stored-xss-in-identity-block"},{"cve":"CVE-2026-66696","cvss":4.3,"epss":0.003,"slug":"cve-2026-66696-kadence-blocks-sensitive-data-exposure-in-gutenberg-editor","title":"Kadence Blocks sensitive data exposure in Gutenberg editor","severity":"medium","exploited":false,"published_at":"2026-08-06T15:17:22.73+00:00","url":"https://junglewise.ai/threats/cve-2026-66696-kadence-blocks-sensitive-data-exposure-in-gutenberg-editor"},{"cve":"CVE-2026-2826","cvss":4.3,"epss":0.003,"slug":"cve-2026-2826-stellarwp-kadence-blocks-authorization-bypass-in-process-pattern","title":"StellarWP Kadence Blocks authorization bypass in process_pattern REST API","severity":"medium","exploited":false,"published_at":"2026-04-04T09:16:20.167+00:00","url":"https://junglewise.ai/threats/cve-2026-2826-stellarwp-kadence-blocks-authorization-bypass-in-process-pattern"},{"cve":"CVE-2026-11357","cvss":4.3,"epss":0.0024,"slug":"cve-2026-11357-stellarwp-kadence-blocks-sensitive-information-exposure-in-editor","title":"StellarWP Kadence Blocks sensitive information exposure in editor_assets_variables","severity":"medium","exploited":false,"published_at":"2026-06-18T06:16:56.703+00:00","url":"https://junglewise.ai/threats/cve-2026-11357-stellarwp-kadence-blocks-sensitive-information-exposure-in-editor"},{"cve":"CVE-2026-15286","cvss":4.3,"slug":"cve-2026-15286-kadence-wp-gutenberg-blocks-unauthorized-post-publication-in-rest","title":"Kadence WP Gutenberg Blocks unauthorized post publication in REST API","severity":"medium","exploited":false,"published_at":"2026-07-10T05:16:31.343+00:00","url":"https://junglewise.ai/threats/cve-2026-15286-kadence-wp-gutenberg-blocks-unauthorized-post-publication-in-rest"},{"cve":"CVE-2026-12902","cvss":4.3,"slug":"cve-2026-12902-stellarwp-kadence-blocks-authorization-bypass-in-prebuilt-library","title":"StellarWP Kadence Blocks authorization bypass in prebuilt library","severity":"medium","exploited":false,"published_at":"2026-07-01T05:16:17.757+00:00","url":"https://junglewise.ai/threats/cve-2026-12902-stellarwp-kadence-blocks-authorization-bypass-in-prebuilt-library"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}