在 Liquid Web / StellarWP 由 Kadence Blocks 开发的 Gutenberg 区块插件中,存在一个“网页生成期间输入中和不当”(即跨站脚本攻击,Cross-site Scripting,XSS)漏洞。该漏洞可导致存储型跨站脚本攻击(Stored XSS)。此问题影响 Kadence Blocks 的 Gutenberg 区块插件,受影响的版本范围是从未知起始版本至 3.7.12。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Liquid Web / StellarWP | Gutenberg Blocks by Kadence Blocks | ≤ 3.7.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Liquid Web / StellarWP | Gutenberg Blocks by Kadence Blocks | 0 ~ 3.7.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66479 | 7.1 HIGH | WordPress WPComplete plugin <= 2.9.5.6 - CSRF to Stored XSS vulnerability |
| CVE-2026-105888 | 5.4 MEDIUM | WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability |
| CVE-2026-106600 | 5.3 MEDIUM | WordPress GiveWP plugin <= 4.18.0 - Broken Access Control vulnerability |
| CVE-2026-105893 | 5.3 MEDIUM | WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability |
| CVE-2026-105891 | 4.3 MEDIUM | WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability |
No comments yet