CVE-2026-18062: The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block Inner Image Content in all versi
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block Inner Image Content in all versions up to, and including, 3.7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only triggerable when the block's urlTransparent attribute is set to a non-empty value, as this is a required precondition for the vulnerable code path in build_html() to be reached.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-18062
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18062 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Kadence Blocks
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-18435: The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnera…nvd · 2026-08-01
- mediumCVE-2026-15286: The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vul…nvd · 2026-07-10
- mediumCVE-2026-12904: The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulner…nvd · 2026-07-01
- mediumCVE-2026-12902: The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnera…nvd · 2026-07-01
More from NVD Recent CVEs
- mediumCVE-2026-6453: The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to …2026-08-01
- mediumCVE-2026-18435: The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnera…2026-08-01
- mediumCVE-2026-18344: The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site …2026-08-01
- mediumCVE-2026-18059: The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to…2026-08-01
- mediumCVE-2026-17605: The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vul…2026-08-01