WordPress Plugin Vulnerabilities

Kadence Blocks < 3.7.6 - Contributor+ Sensitive Information Exposure via Block Editor proData Localization

Description

The plugin discloses the connected Kadence account's license key, license owner email, API key, API email, and license domain to the block editor client context, making it possible for authenticated attackers with Contributor-level access and above to read this credential bundle directly from the browser. Exploitation requires that an administrator has previously connected a valid Kadence license.

Affects Plugins

Fixed in 3.7.6

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
se1en
Verified
No

Timeline

Publicly Published
2026-06-17 (about 2 months ago)
Added
2026-06-18 (about 2 months ago)
Last Updated
2026-06-18 (about 2 months ago)

Other