SecAlerts
kadencewp logo

kadencewp

Security Risk Profile

25
/100
low

Security Risk Score

Comprehensive risk assessment based on 30 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from October 25, 2022 to present

30
Total CVEs
6
Critical+High
0
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
25/100
low

Severity Distribution

Critical
0
High
6
Medium
24
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
11

Age Distribution

Common Weaknesses (CWE)

1
XSS
21
2
SSRF
3
3
Infoleak
1
4
CSRF
1

Most Affected Products

1. Kadencewp Gutenberg Blocks With Ai Wordpress25
2. Kadence WP Gutenberg Blocks7
3. Kadence Gutenberg Blocks6
4. Kadence WP Gutenberg Blocks with AI4
5. Kadence WP Kadence Blocks3

Recent Vulnerabilities

See more →
CVE-2026-11357
CVSS 4.3medium

Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization

6/18/2026🔧 No Patch
CVE-2025-5678
CVSS 6.4medium

Kadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter

7/9/2025🔧 No Patch
CVE-2025-24753
CVSS 8.8EPSS 0%high

WordPress Kadence Blocks plugin <= 3.3.1 - Broken Access Control vulnerability

1/24/2025
CVE-2024-12304
CVSS 6.4medium

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link

1/11/2025
CVE-2024-12581
CVSS 4.8medium

Kadence Blocks <= 3.2.53 - Authenticated (Admin+) Stored Cross-Site Scripting

12/13/2024🔧 No Patch
CVE-2024-10637
CVSS 5.4medium

Kadence Blocks < 3.2.54 - Admin+ Stored XSS

12/12/2024🔧 No Patch
CVE-2024-10785
CVSS 6.4medium

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

11/21/2024
CVE-2024-9655
CVSS 6.4EPSS 0%medium

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Widget

11/1/2024
CVE-2024-6884
CVSS 5.4EPSS 0%medium

Gutenberg Blocks with AI by Kadence WP < 3.2.39 - Contributor+ Stored XSS

8/8/2024🔧 No Patch
CVE-2024-5819
CVSS 6.4EPSS 0%medium

Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.2.45 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data Attributes

6/29/2024🔧 No Patch

Monitor kadencewp in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.