PatchSiren cyber security CVE debrief
CVE-2026-18062 stellarwp CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T09:17:02.100Z and has not been modified since then. The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block Inner Image Content in all versions up to, and including, 3.7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only triggerable when the block's urlTransparent attribute is set to a non-empty value, as this is a required precondition for the vulnerable code path in build_html() to be reached. Users of the Kadence Blocks plugin, particularly those with contributor-level access, should be aware of this vulnerability and take steps to mitigate it.
- Vendor
- stellarwp
- Product
- Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-01
- Original CVE updated
- 2026-08-01
- Advisory published
- 2026-08-01
- Advisory updated
- 2026-08-01
Who should care
Users of the Kadence Blocks plugin, particularly those with contributor-level access, should be aware of this vulnerability and take steps to mitigate it. This includes verifying installed plugin versions, restricting contributor-level access, and implementing additional input sanitization and output escaping for Identity Block Inner Image Content. Security teams should prioritize patching and monitor for suspicious activity and injected scripts across affected deployments, especially in environments where contributor access is widespread or where the plugin's functionality is critical to operations. Vulnerability management processes should include reviewing compensating controls for exposed systems while remediation is scheduled and verified, and tracking exceptions and retesting remediated assets to ensure thorough mitigation. Additionally, operators of WordPress sites using this plugin should assess their exposure and review their incident response plans to handle potential script injection attacks. Platform administrators should also ensure that logging and monitoring are adequate to detect potential exploitation attempts. This vulnerability's impact on operational security and potential for exploitation make it a priority for security teams to address promptly and thoroughly across all affected systems and deployments, especially given the plugin's widespread use and the potential for significant impact if exploited. Security teams should also consider the potential for attackers to leverage this vulnerability as part of a broader attack strategy, possibly combining it with other vulnerabilities or tactics to achieve more significant effects. Therefore, a comprehensive review of affected systems, thorough mitigation, and ongoing monitoring are crucial to minimizing risk and preventing potential breaches or disruptions. The vulnerability's characteristics and potential impact underscore the importance of prompt action and thorough mitigation to protect against potential exploitation and minimize risk effectively across all affected deployments and environments where the plugin is used, particularly in contexts where contributor access is common or where the
Technical summary
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block Inner Image Content in all versions up to, and including, 3.7.8.1. This requires the block's urlTransparent attribute to be set to a non-empty value, allowing authenticated attackers with contributor-level access to inject web scripts. The vulnerability is due to insufficient input sanitization and output escaping. Defenders should verify installed plugin versions, assess contributor access levels, and monitor for suspicious activity and injected scripts.
Defensive priority
Authenticated attackers with contributor-level access could inject web scripts via the Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin, requiring the block's urlTransparent attribute to be set.
Recommended defensive actions
- Inventory and verify installed Kadence Blocks plugin versions up to 3.7.8.1
- Restrict contributor-level access and above
- Implement additional input sanitization and output escaping for Identity Block Inner Image Content
- Monitor for suspicious activity and injected scripts
- Apply vendor remediation when available
Evidence notes
The Kadence Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block Inner Image Content due to insufficient input sanitization and output escaping. This requires contributor-level access and a non-empty urlTransparent attribute. Defenders should verify installed plugin versions, assess contributor access levels, and monitor for suspicious activity and injected scripts.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T09:17:02.100Z and has not been modified since then.