SecAlerts
kadence logo

kadence

Security Risk Profile

57
/100
medium

Security Risk Score

Comprehensive risk assessment based on 13 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 28, 2024 to present

13
Total CVEs
5
Critical+High
0
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
57/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
1
High
4
Medium
8
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
XSS
7
2
SSRF
3

Most Affected Products

1. Kadencewp Gutenberg Blocks With Ai Wordpress9
2. Kadence Gutenberg Blocks7
3. Kadence WP Gutenberg Blocks3
4. Kadence WooCommerce Email Designer2
5. Kadence Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress1

Recent Vulnerabilities

See more →
CVE-2026-28005
CVSS 9.8critical

WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Escalation vulnerability

8/6/2026🔧 No Patch
CVE-2026-12904
CVSS 4.3medium

Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter

7/1/2026🔧 No Patch
CVE-2025-13387
CVSS 7.2high

Kadence WooCommerce Email Designer <= 1.5.17 - Unauthenticated Stored Cross-Site Scripting

12/2/2025🔧 No Patch
CVE-2025-1291
CVSS 6.4medium

Gutenberg Blocks by Kadence Blocks <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon'

3/1/2025🔧 No Patch
CVE-2025-24753
CVSS 8.8EPSS 0%high

WordPress Kadence Blocks plugin <= 3.3.1 - Broken Access Control vulnerability

1/24/2025
CVE-2024-3189
CVSS 5.4medium

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting

5/15/2024
CVE-2024-2273
CVSS 6.4medium

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.34 - Authenticated (Contributor+) Stored Cross-Site Scripting

5/2/2024🔧 No Patch
CVE-2024-1999
CVSS 6.4medium

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.2.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Widget

4/9/2024
CVE-2023-6964
CVSS 8.5high

Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF)

4/9/2024🔧 No Patch
CVE-2024-0598
CVSS 4.8medium

Gutenberg Blocks by Kadence Blocks <= 3.2.17 - Authenticated(Editor+) Stored Cross-Site Scripting via Contact Form Message Settings

4/9/2024

Monitor kadence in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

kadence Security Vulnerabilities & Risk Score | 13 CVEs | SecAlerts - SecAlerts