Nexcess Kadence Blocks是Nexcess公司的一款构建网站内容的框架。 Nexcess Kadence Blocks 3.7.7及之前版本存在授权问题漏洞,该漏洞源于不安全的直接对象引用,由于在Optimize_Rest_Controller的create_item()、get_item()、delete_item()和bulk_delete_items()端点中,用于授权的对象与实际访问的对象之间存在不匹配,授权检查通过current_user_can('edit_post'/'de
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | ≤ 3.7.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | 0 ~ 3.7.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13246 | 6.4 MEDIUM | GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shor |
| CVE-2026-11981 | 4.3 MEDIUM | GiveWP <= 4.15.3 - Cross-Site Request Forgery |
| CVE-2026-12902 | 4.3 MEDIUM | Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary |
No comments yet