PT-2026-20288 · WordPress+1 · Wordpress+1

Ali Sünbül

·

Published

2026-02-18

·

Updated

2026-02-18

·

CVE-2026-1857

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gutenberg Blocks with AI by Kadence WP plugin for WordPress versions up to and including 3.6.1
Description The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is susceptible to Server-Side Request Forgery due to inadequate validation of the endpoint parameter within the get items() function of the GetResponse REST API handler. The permission check for the endpoint parameter only requires the edit posts capability, allowing attackers with Contributor-level access or higher to make server-side requests to arbitrary endpoints on the configured GetResponse API server. This can lead to the retrieval of sensitive data, including contacts, campaigns, and mailing lists, using the site’s stored API credentials. The stored API key is also exposed in the request headers.
Recommendations Update the Gutenberg Blocks with AI by Kadence WP plugin for WordPress to a version later than 3.6.1.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1857

Affected Products

Gutenberg Blocks With Ai
Wordpress