CVE-2025-1625: Qi Blocks < 1.4 - Contributor+ Stored XSS via Counter Block
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1625?
CVE-2025-1625 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-1625?
To fix CVE-2025-1625, update the Qi Blocks WordPress plugin to version 1.4 or later.
Who is affected by CVE-2025-1625?
Users with contributor roles and above are affected by CVE-2025-1625 due to insufficient validation and escaping of block options.
What are the potential impacts of CVE-2025-1625?
The potential impacts of CVE-2025-1625 include unauthorized execution of scripts in the context of users visiting affected pages.
When was CVE-2025-1625 disclosed?
CVE-2025-1625 was disclosed prior to the release of the fixed version 1.4 of the Qi Blocks plugin.