PT-2026-20288 · WordPress+1 · Wordpress+1
Ali Sünbül
·
Published
2026-02-18
·
Updated
2026-02-18
·
CVE-2026-1857
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Gutenberg Blocks with AI by Kadence WP plugin for WordPress versions up to and including 3.6.1
Description
The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is susceptible to Server-Side Request Forgery due to inadequate validation of the
endpoint parameter within the get items() function of the GetResponse REST API handler. The permission check for the endpoint parameter only requires the edit posts capability, allowing attackers with Contributor-level access or higher to make server-side requests to arbitrary endpoints on the configured GetResponse API server. This can lead to the retrieval of sensitive data, including contacts, campaigns, and mailing lists, using the site’s stored API credentials. The stored API key is also exposed in the request headers.Recommendations
Update the Gutenberg Blocks with AI by Kadence WP plugin for WordPress to a version later than 3.6.1.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gutenberg Blocks With Ai
Wordpress