Sceawere
Vulnerability Detail
CVE-2026-104762UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Kadence Blocks Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 2h ago
- Vendor
- stellarwp
- Product
- Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Block Font Family Attribute in all versions up to, and including, 3.7.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This encoding bypass is only triggered when the "Load Google Fonts Locally" site option (kadence_blocks_font_settings['load_fonts_local']) is enabled, which is not the default configuration.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-10T06:16:39.707Z",
"pubdate": "2026-10-10T06:16:39.707Z",
"executiveSummary": "The Kadence Blocks — Page Builder Toolkit plugin for WordPress, in versions up to and including 3.7.12, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from inadequate input sanitization and output escaping within the Block Font Family attribute processing logic.\nThe vulnerability allows authenticated attackers with author-level privileges or higher to inject malicious JavaScript payloads into page content. These scripts execute in the browser of any user who views the affected page, including high-privileged administrators.\nThe exploit path is conditional, requiring the 'Load Google Fonts Locally' (kadence_blocks_font_settings['load_fonts_local']) site configuration to be enabled. While not a default setting, this creates a significant risk profile for sites where local font loading is implemented, potentially leading to unauthorized data access, session hijacking, or administrative action performance through the compromised user context.",
"technicalDetails": "The vulnerability resides in the handling of the 'Block Font Family' attribute within the Kadence Blocks plugin. The root cause is the failure to properly sanitize user-supplied input before storing it in the database and the subsequent failure to escape this data upon rendering in the front-end interface.\nThe exploitation process occurs within the Gutenberg block configuration context. An attacker with author-level access can manipulate the Font Family attribute to include malicious script tags or JavaScript event handlers. When the site configuration kadence_blocks_font_settings['load_fonts_local'] is enabled, the plugin's internal logic processes these font attributes in a manner that bypasses existing encoding mechanisms. This failure in the sanitization chain allows the injected payload to be rendered as active, executable content within the document object model (DOM) of the page.\nThe attack flow proceeds as follows: First, the attacker authenticates as a user with sufficient privileges (Author or higher) to edit pages or blocks. Second, the attacker interacts with the Kadence Blocks configuration for a specific page, specifically targeting the Font Family attribute, and injects an XSS payload. Third, the plugin saves this payload into the WordPress database without stripping the script tags or encoding the dangerous characters. Finally, whenever an unsuspecting user, such as an administrator, views the compromised page, the browser parses the stored malicious script as legitimate code. Because the script executes within the context of the user's active session, the attacker can leverage the victim's privileges to perform unauthorized actions, exfiltrate sensitive data, or perform further site-wide modifications. The reliance on the 'Load Google Fonts Locally' feature suggests that the vulnerability may be tied to how the plugin generates font-related CSS or style tags, where the improperly sanitized attribute is dynamically injected into the stylesheet or HTML attributes without being subjected to standard output escaping functions like esc_html() or esc_attr()."
}