CVE-2025-1627: Qi Blocks < 1.4 - Contributor+ Stored XSS via ToC Block
Published May 19, 2025
·Updated
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
2 affected components
Qi Blocks Qi Blocks<1.4
Qodeinteractive Qi Blocks Wordpress<1.4
Event History
May 19, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-1627?
CVE-2025-1627 has a critical severity level due to its potential for allowing Stored Cross-Site Scripting attacks.
2
How do I fix CVE-2025-1627?
To fix CVE-2025-1627, update the Qi Blocks WordPress plugin to version 1.4 or later.
3
Who is affected by CVE-2025-1627?
The vulnerability affects users with contributor roles and above in the Qi Blocks WordPress plugin.
4
What type of vulnerability is CVE-2025-1627?
CVE-2025-1627 is a Stored Cross-Site Scripting (XSS) vulnerability.
5
What versions of the Qi Blocks plugin are affected by CVE-2025-1627?
Versions of the Qi Blocks plugin before 1.4 are affected by CVE-2025-1627.