CVE-2026-15286 MEDIUM

CVE-2026-15286: Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication

Vendor Stellarwp
Product Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
Weakness CWE-863 · Incorrect authorization
Published July 10, 2026
Last update July 10, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post publication in all versions up to, and including, 3.5.32 due to a misconfigured capability check on the 'get_items_permission_check' function permission callback of the 'process_pattern' REST API endpoint. This makes it possible for authenticated attackers, with Contributor-level access and above, to create and immediately publish posts of any type (including pages), bypassing the standard WordPress review workflow where contributors must submit posts for administrator approval.

Explanation of Vulnerability in Simple Terms

02Summary

Kadence Blocks contains an authorization flaw that allows authenticated users with low privileges to modify content they should not have access to. The vulnerability affects all versions up to 3.5.32. An attacker with a basic user account can alter page builder settings or content without proper permission checks. Update to a version newer than 3.5.32 to resolve this issue.

What an attacker can do

03Attacker Capabilities

Modify page builder content or settings without proper authorization.

Potential impact on your site

04Site Impact

Unauthorized users can alter page layouts, blocks, or content managed through Kadence Blocks.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege authenticated account on the WordPress site.

Key dates

06Disclosure timeline

July 10, 2026 CVE published
July 10, 2026 Record updated

Related vulnerabilities

08Related CVE