CVE-2026-2633 PUBLISHED

Gutenberg Blocks with AI by Kadence WP <= 3.6.1 - Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload

Assigner: Wordfence
Reserved: 17.02.2026 Published: 18.02.2026 Updated: 18.02.2026

The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.1. This is due to a missing capability check in the process_image_data_ajax_callback() function which handles the kadence_import_process_image_data AJAX action. The function's authorization check via verify_ajax_call() only validates edit_posts capability but fails to check for the upload_files capability. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary images from remote URLs to the WordPress Media Library, bypassing the standard WordPress capability restriction that prevents Contributors from uploading files.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 4.3

Product Status

Vendor stellarwp
Product Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
Versions Default: unaffected
  • affected from * to 3.6.1 (incl.)

Credits

  • Ali Sünbül finder

References

Problem Types

  • CWE-862 Missing Authorization CWE