Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter
medium
The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.9 via the 'page_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to modify the stored Qi...
- CVSS:
- 4.3
- Affected:
- up to 1.4.9
- Fixed in:
- 1.5.0
- Disclosed:
- Jun 30, 2026
CVE-2026-10096 on NVD →
Qi Blocks <= 1.4.3 - Missing Authorization to Arbitrary Attachment Resize
medium
The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up to, and including, 1.4.3. This is due to the plugin not properly verifying that a user has permission to resize a specific attachment. This makes it poss...
- CVSS:
- 4.3
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Nov 14, 2025
CVE-2025-12182 on NVD →
Qi Blocks <= 1.4.3 - Missing Authorization to Authenticated (Contributor+) Plugin Settings Update
medium
The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. This is due to the plugin storing arbitrary CSS styles submitted via the `qi-blocks/v1/update-styles` REST API endpoint without proper sanitization in the `update_global_styles_callback()` function. Th...
- CVSS:
- 4.3
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Oct 31, 2025
CVE-2025-12180 on NVD →
Qi Blocks <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Aug 11, 2025
CVE-2025-64383 on NVD →
Qi Blocks <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Block
medium
The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages th...
- CVSS:
- 5.4
- Affected:
- up to 1.3.6
- Fixed in:
- 1.4
- Disclosed:
- Apr 28, 2025
CVE-2025-1626 on NVD →
Qi Blocks <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Counter Block
medium
The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages th...
- CVSS:
- 5.4
- Affected:
- up to 1.3.6
- Fixed in:
- 1.4
- Disclosed:
- Apr 28, 2025
CVE-2025-1625 on NVD →
Qi Blocks <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ToC Block
medium
The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages th...
- CVSS:
- 5.4
- Affected:
- up to 1.3.6
- Fixed in:
- 1.4
- Disclosed:
- Apr 28, 2025
CVE-2025-1627 on NVD →
Qi Blocks <= 1.3.2 - Authenticated (Contributor+) Local File Inclusion
high
The Qi Blocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...
- CVSS:
- 8.8
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.3
- Disclosed:
- Oct 21, 2024
CVE-2024-49690 on NVD →
Qi Blocks <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 1.3
- Fixed in:
- 1.3.1
- Disclosed:
- Jul 11, 2024
CVE-2024-38712 on NVD →
Qi Blocks <= 1.2.9 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitra...
- CVSS:
- 6.4
- Affected:
- up to 1.2.9
- Fixed in:
- 1.3.0
- Disclosed:
- Jun 5, 2024
CVE-2024-5221 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database