SecAlerts
kadence wp logo

kadence wp

Security Risk Profile

31
/100
low

Security Risk Score

Comprehensive risk assessment based on 16 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from May 10, 2024 to present

16
Total CVEs
2
Critical+High
0
Exploited
0
Unpatched

Threat Assessment

Avg CVSS
6.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
31/100
low

Severity Distribution

Critical
1
High
1
Medium
14
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
9

Age Distribution

Common Weaknesses (CWE)

1
XSS
13
2
Malicious File Upload
1

Most Affected Products

1. Kadencewp Gutenberg Blocks With Ai Wordpress13
2. Kadence WP Kadence Blocks4
3. Kadence WP Gutenberg Blocks with AI4
4. Kadence WP Gutenberg Blocks4
5. Kadence WP Kadence WooCommerce Email Designer2

Recent Vulnerabilities

See more →
CVE-2026-2826
CVSS 4.3medium

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media Upload

4/4/2026🔧 No Patch
CVE-2025-54697
CVSS 7.2high

WordPress Kadence WooCommerce Email Designer Plugin <= 1.5.16 - Privilege Escalation Vulnerability

8/14/2025
CVE-2025-5678
CVSS 6.4medium

Kadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter

7/9/2025🔧 No Patch
CVE-2025-39557
CVSS 9.1EPSS 0%critical

WordPress Kadence WooCommerce Email Designer plugin <= 1.5.14 - Arbitrary File Upload vulnerability

4/16/2025
CVE-2024-12304
CVSS 6.4medium

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link

1/11/2025
CVE-2024-12581
CVSS 4.8medium

Kadence Blocks <= 3.2.53 - Authenticated (Admin+) Stored Cross-Site Scripting

12/13/2024🔧 No Patch
CVE-2024-10637
CVSS 5.4medium

Kadence Blocks < 3.2.54 - Admin+ Stored XSS

12/12/2024🔧 No Patch
CVE-2024-10785
CVSS 6.4medium

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

11/21/2024
CVE-2024-9655
CVSS 6.4EPSS 0%medium

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Widget

11/1/2024
CVE-2024-6884
CVSS 5.4EPSS 0%medium

Gutenberg Blocks with AI by Kadence WP < 3.2.39 - Contributor+ Stored XSS

8/8/2024🔧 No Patch

Monitor kadence wp in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

kadence wp Security Vulnerabilities & Risk Score | 16 CVEs | SecAlerts - SecAlerts