The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up to, and including, 1.4.3. This is due to the plugin not properly verifying that a user has permission to resize a specific attachment. This makes it possible for authenticated attackers, with Contributor-level access and above, to resize arbitrary media library images belonging to other users, which can result in unintended file writes, disk consumption, and server resource abuse through processing of large images.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 15 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qodeinteractive
Qodeinteractive qi Blocks Wordpress Wordpress wordpress |
|
| Vendors & Products |
Qodeinteractive
Qodeinteractive qi Blocks Wordpress Wordpress wordpress |
Sat, 15 Nov 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up to, and including, 1.4.3. This is due to the plugin not properly verifying that a user has permission to resize a specific attachment. This makes it possible for authenticated attackers, with Contributor-level access and above, to resize arbitrary media library images belonging to other users, which can result in unintended file writes, disk consumption, and server resource abuse through processing of large images. | |
| Title | Qi Blocks <= 1.4.3 - Missing Authorization to Arbitrary Attachment Resize | |
| Weaknesses | CWE-284 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-15T03:27:01.199Z
Updated: 2025-11-17T18:41:49.941Z
Reserved: 2025-10-24T19:16:49.591Z
Link: CVE-2025-12182
Updated: 2025-11-17T18:41:46.347Z
Status : Awaiting Analysis
Published: 2025-11-15T04:15:55.570
Modified: 2025-11-18T14:06:55.963
Link: CVE-2025-12182
No data.