CVE-2026-11357: Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.5 via the editorassetsvariables. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the site's connected Kadence account license key, license owner email, apikey, apiemail, and license domain from the browser console by inspecting window.kadenceblocksparams.proData. Exploitation requires only that an administrator has previously connected a valid Kadence license; the full credential bundle is then readable by any Contributor-level user from the block editor client context without any server-side request manipulation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Kadence Blocks — Page Builder Toolkit for Gutenberg Editorfrom your environment.If the plugin is not required, uninstall the Kadence Blocks plugin from the site to eliminate the exposure of license and API credentials in the block editor client context.
- Configuration
If an administrator has previously connected a Kadence license, disconnect the site from the Kadence account (remove/unlink the license) to prevent license and API credentials from being present in the block editor client context.
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor (license connection) license_connected = disconnect - Configuration
Revoke block editor access for Contributor-level users (for example, remove the ability to access the block editor or edit_posts capability via a role editor plugin or custom capability management) so they cannot open the block editor and read window.kadence_blocks_params.proData.
WordPress roles/capabilities (Contributor+) block editor access / edit_posts capability = disabled for Contributors - Compensating control
Restrict access to the block editor and related wp-admin/edit-site pages to trusted IP addresses or administrative networks (via firewall, WAF, or reverse-proxy rules) to limit which authenticated users can reach the client context exposing proData.
- Operational
Rotate any Kadence account credentials that may have been exposed (license key, license owner email, api_key, api_email, license domain) and update/disconnect/reissue licenses as necessary after remediation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11357?
The severity of CVE-2026-11357 is medium, rated at 4.3.
How do I fix CVE-2026-11357?
To fix CVE-2026-11357, update the Kadence Blocks plugin to version 3.7.6 or later.
Who is affected by CVE-2026-11357?
CVE-2026-11357 affects users of Kadence Blocks version 3.7.5 and earlier with contributor-level access and above.
What type of vulnerability is CVE-2026-11357?
CVE-2026-11357 is categorized as a Sensitive Information Exposure vulnerability.
What versions of Kadence Blocks are vulnerable to CVE-2026-11357?
All versions of Kadence Blocks up to and including 3.7.5 are vulnerable to CVE-2026-11357.