PT-2026-30315 · WordPress · Kadence Blocks — Page Builder Toolkit For Gutenberg Editor
Lukasz Sobanski
·
Published
2026-04-04
·
Updated
2026-04-04
·
CVE-2026-2826
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress versions up to and including 3.6.3
Description
The Kadence Blocks plugin for WordPress does not properly verify the
upload files capability for users accessing the process pattern API endpoint. This allows authenticated attackers with contributor-level access or higher to upload images to the WordPress Media Library by providing remote image URLs, which the server then downloads and creates as media attachments.Recommendations
Update Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress to a version later than 3.6.3.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kadence Blocks — Page Builder Toolkit For Gutenberg Editor