The Kadence Blocks — Page Builder Toolkit for Gutenberg...
Moderate severity
Unreviewed
Published
Apr 4, 2026
to the GitHub Advisory Database
•
Updated Apr 4, 2026
Description
Published by the National Vulnerability Database
Apr 4, 2026
Published to the GitHub Advisory Database
Apr 4, 2026
Last updated
Apr 4, 2026
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user has the
upload_filescapability in theprocess_patternREST API endpoint. This makes it possible for authenticated attackers, with contributor level access and above, to upload images to the WordPress Media Library by supplying remote image URLs that the server downloads and creates as media attachments.References