Kadencewp develops a suite of WordPress plugins and design tools, notably Gutenberg Blocks with AI, Kadence Blocks Pro, and WooCommerce email designer, that extend WordPress's page-building and e-commerce functionality. The vendor's vulnerability footprint, while modest in volume, reflects the web-facing and plugin architecture of these products: the recurring weakness classes center on input-handling issues including cross-site scripting, server-side request forgery, and cross-site request forgery, alongside deserialization risks typical of PHP-based WordPress extensions. The products operate in a heavily deployed CMS ecosystem where even narrowly scoped plugins can affect a large installed base of sites, making these input and request-validation flaws a persistent concern for WordPress administrators. Defenders tracking this vendor should prioritize plugin updates as part of their broader WordPress security posture and monitor for vulnerabilities in the design-tool and e-commerce modules especially. Live severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kadencewp over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3679HIGH The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which could lead to PHP object injection issues when an admin impor | Jan 9, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-47186HIGH Cross-Site Request Forgery (CSRF) vulnerability in Kadence WP Kadence WooCommerce Email Designer plugin <= 1.5.11 versions. | Nov 6, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-3335HIGH The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin im | Oct 25, 2022 | 7.2 | 24 | NO | NO |
CVE-2025-24753HIGH Missing Authorization vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issu | Jan 24, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-12304MEDIUM The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via button block link in all versions up to, an | Jan 11, 2025 | 5.4 | 20 | NO | NO |
CVE-2024-1999MEDIUM The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget's anchor style parameter | Apr 9, 2024 | 5.4 | 20 | NO | NO |
CVE-2024-2509MEDIUM The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in a page/post where the bl | Apr 5, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-1330MEDIUM The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using some of its shortcode's functionalities to leak arbitrary optio | Jun 27, 2024 | 4.3 | 19 | NO | NO |
CVE-2024-4863MEDIUM The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘titleFont’ parameter in all versions u | Jun 14, 2024 | 5.4 | 19 | NO | NO |
CVE-2024-4057MEDIUM The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.37 does not validate and escape some of its block attributes before outputting them back in a page/post wher | Jun 4, 2024 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kadencewp.
Media articles that mention a CVE ID that affects a product developed by Kadencewp — matched by CVE ID, not by vendor name.