CVE-2026-103354: WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.11.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.7.11.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Gutenberg Blocks by Kadence Blocksto a version that resolves this vulnerability.Fixed in 3.7.12
Event History
Frequently Asked Questions
Which installations are affected?
Gutenberg Blocks by Kadence Blocks versions through 3.7.11.1 are affected. The available data does not identify a lower affected version, indicating the issue applies from an unspecified starting version through 3.7.11.1.
Does exploitation require authentication or user interaction?
The CVSS vector indicates no attacker privileges are required, but user interaction is required. The available data does not specify what interaction is needed or where the malicious content is rendered.
What is the potential impact of successful exploitation?
This is a stored XSS issue. The supplied severity vector indicates low confidentiality, integrity, and availability impact, with scope changed.