Sceawere
Vulnerability Detail
CVE-2026-103354UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Kadence Blocks
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 4h ago
- Vendor
- Liquid Web / StellarWP
- Product
- Gutenberg Blocks by Kadence Blocks
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.7.11.1.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-04T09:16:38.683Z",
"pubdate": "2026-10-04T09:16:38.683Z",
"executiveSummary": "The vulnerability identified in Gutenberg Blocks by Kadence Blocks is an Improper Neutralization of Input During Web Page Generation, classified as a Stored Cross-Site Scripting (XSS) vulnerability.\nThis security flaw affects all versions of the product from n/a through 3.7.11.1.\nThe vulnerability allows an authenticated attacker to inject arbitrary malicious JavaScript into stored content within the WordPress environment.\nWhen a victim, such as an administrator or another user, views the affected post or page where the malicious content is embedded, the injected script executes within the context of the victim's session.\nThis leads to significant security risks, including the potential for session hijacking, unauthorized actions performed on behalf of the user, credential theft, and defacement of the affected website.\nBecause this is a stored XSS vulnerability, the payload persists on the server and is triggered whenever the compromised component is rendered.\nExploitation requires the attacker to have sufficient permissions to create or edit content using the affected blocks within the WordPress Gutenberg editor.",
"technicalDetails": "The root cause of this vulnerability lies in the improper sanitization and validation of user-supplied data within the Gutenberg Blocks by Kadence Blocks plugin. Specifically, the plugin fails to adequately neutralize malicious input when saving block attributes or settings that are later rendered in the browser.\nIn the context of the WordPress block editor, block attributes are often serialized and saved to the database. If these attributes are not properly escaped or sanitized during the saving process, or if they are rendered without proper output encoding, they become vectors for XSS.\nThe attack flow proceeds as follows: First, an authenticated attacker with permissions to edit posts or pages utilizes the vulnerable Kadence Blocks component. Second, the attacker injects a malicious payload, such as a script tag containing arbitrary JavaScript, into a vulnerable block attribute field. Third, the plugin saves this payload into the WordPress database without applying sufficient sanitization filters.\nOnce the post is saved, the payload is stored persistently. Fourth, whenever a user (such as an administrator or editor) navigates to the page or post containing the compromised block, the application retrieves the malicious payload from the database and renders it directly into the HTML output without adequate output encoding.\nThe victim's browser interprets the injected script as legitimate code originating from the trusted domain. Consequently, the browser executes the payload within the security context of the victim's current session.\nThe impact of a successful exploitation is severe. Because the script runs in the context of the victim's session, it inherits the victim's privileges. If an administrator is targeted, the attacker could theoretically perform any action the administrator can perform, such as creating new administrative users, installing malicious plugins, changing site settings, or redirecting visitors to malicious third-party websites.\nThe affected versions are Gutenberg Blocks by Kadence Blocks, from n/a through 3.7.11.1. The vulnerability is characterized by its persistent nature, meaning the malicious script remains active until the specific block is updated or the database entry is manually cleaned. This vulnerability highlights the critical importance of implementing robust input sanitization and context-aware output encoding across all plugin components that handle user-supplied data in the Gutenberg ecosystem."
}