CVE-2025-1626: Qi Blocks < 1.4 - Contributor+ Stored XSS vi Countdown Block
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1626?
CVE-2025-1626 is classified as a moderate severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-1626?
To fix CVE-2025-1626, update the Qi Blocks WordPress plugin to version 1.4 or later.
Who is affected by CVE-2025-1626?
All users of the Qi Blocks WordPress plugin prior to version 1.4 are affected by CVE-2025-1626.
What type of attacks does CVE-2025-1626 allow?
CVE-2025-1626 allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
What caused CVE-2025-1626?
CVE-2025-1626 was caused by the Qi Blocks plugin's failure to validate and escape Countdown block options before output.