PT-2025-47039 · WordPress · Qi Blocks
Adrian Lukita
·
Published
2025-11-15
·
Updated
2025-11-15
·
CVE-2025-12182
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Qi Blocks versions prior to 1.4.4
Description
The Qi Blocks plugin for WordPress has a flaw that allows unauthorized access due to a missing capability check on the
resize image callback() function. This occurs because the plugin does not verify if a user has the necessary permission to resize a specific attachment. Authenticated attackers with Contributor-level access or higher can resize media library images belonging to other users. This can lead to unintended file writes, increased disk consumption, and server resource abuse through the processing of large images.Recommendations
Update Qi Blocks to version 1.4.4 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qi Blocks