Input validation vulnerability in Gutenberg Blocks with AI by Kadence WP – Page Builder Features 3.3.3

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress has a security issue that allows for Stored Cross-Site Scripting. This means that there is not enough protection in place to prevent malicious code from being injected into pages using the ‘Countdown’ widget. This can be done by attackers who have been granted Contributor-level access or higher. When a user visits one of these pages, the injected code will run.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.