These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The Membership Plugin – Kadence Memberships plugin for WordPress, formerly Restrict Content, is vulnerable to password reset link poisoning leading to account takeover. This critical vulnerability exists in all versions up to, and including, 4.0.0 due to the legacy lost-password handler rc_process_lost_password_form() consuming the attacker-controlled rc_redirect POST parameter into two unvalidated sinks. [truncated]
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'toggleIcon' Block Attribute in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T09:17:02.100Z and has not been modified since then. The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block Inner Image Content in all versions up to, and including, 3.7.8.1 due to insufficient input sanit [truncated]
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with give worker-level access and above to inject arbitrary web scripts in pages that [truncated]
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post publication in all versions up to, and including, 3.5.32 due to a misconfigured capability check on the 'get_items_permission_check' function permission callback of the 'process_pattern' REST API endpoint. This vulnerability allows authenticated attackers with Contributor-level access [truncated]
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress, up to and including version 3.7.5, exposes sensitive information. Authenticated attackers with contributor-level access can extract the site's connected Kadence account license key, license owner email, API key, API email, and license domain. This is possible by inspecting window.kadence_blocks_params.proData in the brows [truncated]
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress has an authorization bypass vulnerability in all versions up to, and including, 3.6.3. This issue allows authenticated attackers with contributor level access and above to upload images to the WordPress Media Library by supplying remote image URLs that the server downloads and creates as media attachments due to insufficie [truncated]