PT-2026-57063 · Kadence Wp · Gutenberg Blocks With Ai
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Gutenberg Blocks with AI by Kadence WP – Page Builder Features versions prior to 3.5.33
Description
An issue exists that allows authenticated users with Contributor-level access or higher to create and immediately publish posts of any type, including pages. This occurs because of a misconfigured capability check within the
get items permission check() function, which serves as the permission callback for the 'process pattern' REST API endpoint. This flaw allows attackers to bypass the standard review workflow that typically requires administrator approval for contributor submissions.Recommendations
Update the plugin to version 3.5.33 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gutenberg Blocks With Ai