PT-2025-47039 · WordPress · Qi Blocks

Adrian Lukita

·

Published

2025-11-15

·

Updated

2025-11-15

·

CVE-2025-12182

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Qi Blocks versions prior to 1.4.4
Description The Qi Blocks plugin for WordPress has a flaw that allows unauthorized access due to a missing capability check on the resize image callback() function. This occurs because the plugin does not verify if a user has the necessary permission to resize a specific attachment. Authenticated attackers with Contributor-level access or higher can resize media library images belonging to other users. This can lead to unintended file writes, increased disk consumption, and server resource abuse through the processing of large images.
Recommendations Update Qi Blocks to version 1.4.4 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-12182

Affected Products

Qi Blocks