What the vulnerability does
01Description
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post publication in all versions up to, and including, 3.5.32 due to a misconfigured capability check on the 'get_items_permission_check' function permission callback of the 'process_pattern' REST API endpoint. This makes it possible for authenticated attackers, with Contributor-level access and above, to create and immediately publish posts of any type (including pages), bypassing the standard WordPress review workflow where contributors must submit posts for administrator approval.
Explanation of Vulnerability in Simple Terms
02Summary
Kadence Blocks contains an authorization flaw that allows authenticated users with low privileges to modify content they should not have access to. The vulnerability affects all versions up to 3.5.32. An attacker with a basic user account can alter page builder settings or content without proper permission checks. Update to a version newer than 3.5.32 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Modify page builder content or settings without proper authorization.
Potential impact on your site
04Site Impact
Unauthorized users can alter page layouts, blocks, or content managed through Kadence Blocks.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege authenticated account on the WordPress site.
Key dates
06Disclosure timeline
July 10, 2026
CVE published
July 10, 2026
Record updated