CVE-2026-66696
Received Received - Intake

Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks

Vulnerability report for CVE-2026-66696, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: Patchstack

Description

Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kadence_blocks gutenberg_blocks to 3.7.8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a sensitive data exposure issue in the WordPress plugin Gutenberg Blocks by Kadence Blocks versions 3.7.8 or lower. It allows users with contributor or developer privileges to access sensitive information that should be restricted, potentially leading to further exploitation.

Detection Guidance

To detect this vulnerability, check the installed version of the Kadence Blocks plugin in your WordPress site. Compare it against version 3.7.8.1. You can do this via the WordPress admin panel under Plugins or by running SQL queries on the database if you have access.

Impact Analysis

If you use an affected version of the Kadence Blocks plugin, an attacker with contributor or developer access could view sensitive data. This could include user information or other restricted details, increasing the risk of data breaches or further attacks.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Exposure of personal or health data could result in legal penalties or loss of trust.

Mitigation Strategies

Immediately update the Kadence Blocks plugin to version 3.7.8.1 or later. If auto-updates are available, enable them for the plugin. Remove any unnecessary contributor or developer-level user accounts to reduce exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66696. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart