WordPress · Kadence Blocks · CVE-2026-11357
**Name of the Vulnerable Software and Affected Versions**
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor versions prior to 3.7.6
**Description**
The plugin is subject to sensitive information exposure through the `editor assets variables`. Authenticated attackers with contributor-level access or higher can extract the connected Kadence account license key, license owner email, `api key`, `api email`, and license domain. This is achieved by inspecting `window.kadence blocks params.proData` within the browser console. The issue occurs if an administrator has previously connected a valid Kadence license, allowing the credential bundle to be read from the block editor client context without requiring server-side request manipulation.
**Recommendations**
Update to a version newer than 3.7.5.