CVE-2025-12182
- EPSS 0.04%
- Veröffentlicht 15.11.2025 03:27:01
- Zuletzt bearbeitet 18.11.2025 14:06:55
The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up to, and including, 1.4.3. This is due to the plugin not properly verifying that a u...
CVE-2025-12180
- EPSS 0.05%
- Veröffentlicht 01.11.2025 05:40:21
- Zuletzt bearbeitet 04.11.2025 15:41:31
The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. This is due to the plugin storing arbitrary CSS styles submitted via the `qi-blocks/v1/update-styles` REST API endpoint without pro...
CVE-2025-1626
- EPSS 0.05%
- Veröffentlicht 19.05.2025 06:15:18
- Zuletzt bearbeitet 09.01.2026 21:16:12
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Sto...
CVE-2025-1627
- EPSS 0.05%
- Veröffentlicht 19.05.2025 06:15:18
- Zuletzt bearbeitet 09.01.2026 21:16:12
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-...
CVE-2025-1625
- EPSS 0.05%
- Veröffentlicht 19.05.2025 06:15:17
- Zuletzt bearbeitet 09.01.2026 21:16:12
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Store...
CVE-2024-49690
- EPSS 1.96%
- Veröffentlicht 23.10.2024 16:15:09
- Zuletzt bearbeitet 26.01.2026 18:23:29
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Interactive Qi Blocks.This issue affects Qi Blocks: from n/a through 1.3.2.
CVE-2024-38712
- EPSS 0.14%
- Veröffentlicht 20.07.2024 08:15:12
- Zuletzt bearbeitet 23.01.2026 19:46:10
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Qode Interactive Qi Blocks allows Stored XSS.This issue affects Qi Blocks: from n/a through 1.3.
CVE-2024-5221
- EPSS 0.2%
- Veröffentlicht 06.06.2024 09:15:14
- Zuletzt bearbeitet 21.11.2024 09:47:12
The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenti...