Input validation vulnerability in Gutenberg Blocks with AI by Kadence WP – Page Builder Features 3.2.37

The Kadence WP plugin for WordPress, which adds special features to the page builder, has a security vulnerability. This vulnerability allows hackers to insert harmful code into pages using a specific feature called “typer effect” in the advanced heading widget. This can happen in all versions up to 3.2.37 because the plugin does not properly protect against and remove harmful code that is added by users. This means that someone with contributor-level access or higher can add code that will run when someone else views the page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.