A vulnerability was found in stellarwp Kadence Blocks Plugin up to 3.7.8 on WordPress and classified as problematic. This affects an unknown function of the component Block Attribute. Executing a manipulation of the argument toggleIcon can lead to cross site scripting.
This vulnerability appears as CVE-2026-18435. The attack may be performed from remote. There is no available exploit.