CVE-2025-64383: WordPress Qi Blocks plugin <= 1.4.3 - Cross Site Scripting (XSS) vulnerability
Published Nov 13, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks allows Stored XSS.This issue affects Qi Blocks: from n/a through <= 1.4.3.
Affected Software
2 affected components
Qode Qi Blocks<=1.4.3
WordPress Qi Blocks plugin<=1.4.3
Event History
Nov 13, 2025
CVE Published
via MITRE·09:24 AM
Data Sourced
via MITRE·09:24 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-64383?
CVE-2025-64383 is classified as a moderate severity vulnerability due to its potential for exploitation through stored XSS.
2
How do I fix CVE-2025-64383?
To fix CVE-2025-64383, update the Qode Qi Blocks to version 1.4.4 or later.
3
What applications are affected by CVE-2025-64383?
CVE-2025-64383 affects the Qode Qi Blocks plugin for WordPress versions up to and including 1.4.3.
4
What type of vulnerability is CVE-2025-64383?
CVE-2025-64383 is categorized as a Stored Cross-site Scripting (XSS) vulnerability.
5
Can CVE-2025-64383 be exploited by attackers?
Yes, CVE-2025-64383 can be exploited by attackers to execute malicious scripts in the context of a user's browser.