Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kadencewp

First CVE: Oct 25, 2022Active for: 4 yearsTotal CVEs: 29
11.4
VTI Score
Low

Kadencewp develops a suite of WordPress plugins and design tools, notably Gutenberg Blocks with AI, Kadence Blocks Pro, and WooCommerce email designer, that extend WordPress's page-building and e-commerce functionality. The vendor's vulnerability footprint, while modest in volume, reflects the web-facing and plugin architecture of these products: the recurring weakness classes center on input-handling issues including cross-site scripting, server-side request forgery, and cross-site request forgery, alongside deserialization risks typical of PHP-based WordPress extensions. The products operate in a heavily deployed CMS ecosystem where even narrowly scoped plugins can affect a large installed base of sites, making these input and request-validation flaws a persistent concern for WordPress administrators. Defenders tracking this vendor should prioritize plugin updates as part of their broader WordPress security posture and monitor for vulnerabilities in the design-tool and e-commerce modules especially. Live severity, exploitation activity, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kadencewp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2022
3 years ago
Most Recent CVE
Jul 9, 2025
380 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-3679HIGH
The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which could lead to PHP object injection issues when an admin impor
Jan 9, 20238.827NONO
CVE-2023-47186HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Kadence WP Kadence WooCommerce Email Designer plugin <= 1.5.11 versions.
Nov 6, 20238.824NONO
CVE-2022-3335HIGH
The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin im
Oct 25, 20227.224NONO
CVE-2025-24753HIGH
Missing Authorization vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issu
Jan 24, 20258.823NONO
CVE-2024-12304MEDIUM
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via button block link in all versions up to, an
Jan 11, 20255.420NONO
CVE-2024-1999MEDIUM
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget's anchor style parameter
Apr 9, 20245.420NONO
CVE-2024-2509MEDIUM
The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in a page/post where the bl
Apr 5, 20246.520NONO
CVE-2024-1330MEDIUM
The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using some of its shortcode's functionalities to leak arbitrary optio
Jun 27, 20244.319NONO
CVE-2024-4863MEDIUM
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘titleFont’ parameter in all versions u
Jun 14, 20245.419NONO
CVE-2024-4057MEDIUM
The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.37 does not validate and escape some of its block attributes before outputting them back in a page/post wher
Jun 4, 20246.119NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
86%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network29 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (20.7%)
Unknown0 (0.0%)
Required23 (79.3%)
Privileges Required
Low23 (79.3%)
High3 (10.3%)
None3 (10.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kadencewp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kadencewp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kadencewp's Products

View all 3 CNAs →

Top CWEs