CVE-2026-11357: Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization

Published Jun 18, 2026
·
Updated

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.5 via the editorassetsvariables. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the site's connected Kadence account license key, license owner email, apikey, apiemail, and license domain from the browser console by inspecting window.kadenceblocksparams.proData. Exploitation requires only that an administrator has previously connected a valid Kadence license; the full credential bundle is then readable by any Contributor-level user from the block editor client context without any server-side request manipulation.

Affected Software

1 affected component
Kadencewp Kadence Blocks<=3.7.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Kadence Blocks — Page Builder Toolkit for Gutenberg Editor from your environment.

    If the plugin is not required, uninstall the Kadence Blocks plugin from the site to eliminate the exposure of license and API credentials in the block editor client context.

  2. Configuration

    If an administrator has previously connected a Kadence license, disconnect the site from the Kadence account (remove/unlink the license) to prevent license and API credentials from being present in the block editor client context.

    Kadence Blocks — Page Builder Toolkit for Gutenberg Editor (license connection) license_connected = disconnect
  3. Configuration

    Revoke block editor access for Contributor-level users (for example, remove the ability to access the block editor or edit_posts capability via a role editor plugin or custom capability management) so they cannot open the block editor and read window.kadence_blocks_params.proData.

    WordPress roles/capabilities (Contributor+) block editor access / edit_posts capability = disabled for Contributors
  4. Compensating control

    Restrict access to the block editor and related wp-admin/edit-site pages to trusted IP addresses or administrative networks (via firewall, WAF, or reverse-proxy rules) to limit which authenticated users can reach the client context exposing proData.

  5. Operational

    Rotate any Kadence account credentials that may have been exposed (license key, license owner email, api_key, api_email, license domain) and update/disconnect/reissue licenses as necessary after remediation.

Event History

Jun 18, 2026
CVE Published
via MITRE·04:31 AM
Data Sourced
via MITRE·04:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-11357?

The severity of CVE-2026-11357 is medium, rated at 4.3.

2

How do I fix CVE-2026-11357?

To fix CVE-2026-11357, update the Kadence Blocks plugin to version 3.7.6 or later.

3

Who is affected by CVE-2026-11357?

CVE-2026-11357 affects users of Kadence Blocks version 3.7.5 and earlier with contributor-level access and above.

4

What type of vulnerability is CVE-2026-11357?

CVE-2026-11357 is categorized as a Sensitive Information Exposure vulnerability.

5

What versions of Kadence Blocks are vulnerable to CVE-2026-11357?

All versions of Kadence Blocks up to and including 3.7.5 are vulnerable to CVE-2026-11357.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203