CVE-2025-1627- Qi Blocks < 1.4 – Contributor+ Stored XSS via ToC Block – POC

CVE-2025-1627- Qi Blocks < 1.4 – Contributor+ Stored XSS via ToC Block – POC

In April 2025, a stored Cross-Site Scripting (XSS) vulnerability was identified in the popular Qi Blocks WordPress plugin, specifically affecting versions below 1.4. This vulnerability, now tracked as CVE-2025-1627, allows a user with Contributor permissions to inject malicious scripts into the site using the Table of Contents (ToC) block. Once a malicious payload is stored, it gets executed every time a visitor loads the affected page — putting both site administrators and end users at risk.

CVE-2025-1625- Qi Blocks < 1.4 – Contributor+ Stored XSS via Counter Block – POC

CVE-2025-1625- Qi Blocks < 1.4 – Contributor+ Stored XSS via Counter Block – POC

Qi Blocks, developed by Qode Interactive, is one of the most comprehensive sets of Gutenberg blocks for WordPress, offering dozens of customizable components. Despite its acclaim for design and functionality, versions of the plugin prior to 1.4 are vulnerable to Stored Cross-Site Scripting (XSS), allowing users with Contributor privileges to inject malicious JavaScript code. This vulnerability poses a serious security threat, as the payload executes in both the admin panel and public pages.

CVE-2025-1626- Qi Blocks < 1.4 – Contributor+ Stored XSS via Countdown Block – POC

CVE-2025-1626- Qi Blocks < 1.4 – Contributor+ Stored XSS via Countdown Block – POC

WordPress plugins expand the functionality of websites but can sometimes introduce security vulnerabilities if user inputs are not properly validated and sanitized. CVE-2025-1626 highlights a critical Stored Cross-Site Scripting (XSS) vulnerability discovered in the popular Qi Blocks plugin (versions prior to 1.4), which could be exploited by users with Contributor privileges. This flaw poses a serious risk to the security of WordPress sites using the plugin, as it could lead to session hijacking, privilege escalation, or complete site compromise.

Plugin Security Certification (PSC-2025-64567): “Simple Custom CSS and JS” – Version 3.50: Use CSS and JS with Enhanced Security

Plugin Security Certification (PSC-2025-64567): “Simple Custom CSS and JS” – Version 3.50: Use CSS and JS with Enhanced Security

Simple Custom CSS and JS is a lightweight yet powerful WordPress plugin that empowers users to inject custom CSS and JavaScript into their websites without altering core theme or plugin files. This plugin is an essential tool for developers and site administrators who require flexibility in styling or scripting, while ensuring a clean and maintainable WordPress environment.

Thanks to its intuitive interface and code editor with syntax highlighting, Simple Custom CSS and JS makes code management straightforward and efficient. Furthermore, the plugin has undergone rigorous security testing and proudly carries the Plugin Security Certification (PSC-2025-64567) issued by CleanTalk, validating its compliance with modern secure coding standards.

Plugin Security Certification (PSC-2025-64566): “Joinchat” – Version 5.2.4: Use Chat with Enhanced Security

Plugin Security Certification (PSC-2025-64566): “Joinchat” – Version 5.2.4: Use Chat with Enhanced Security

JoinChat is a powerful communication plugin designed to enhance user engagement by integrating WhatsApp and other chat platforms directly into your WordPress website. With its intuitive interface, JoinChat enables site owners to place a floating contact button that connects users to WhatsApp on mobile and desktop, delivering real-time, personalized support. JoinChat supports multiple customization options, analytics integration, WooCommerce compatibility, and dynamic content for each page or product.

Beyond functionality, JoinChat stands out with its emphasis on code quality and security. The plugin has successfully passed a full-scale security audit and has been awarded the Plugin Security Certification (PSC-2025-645656 by CleanTalk, assuring WordPress site owners of a safe and robust integration with modern messaging tools.

Plugin Security Certification (PSC-2024-64565): “WooCommerce Shipping & Tax” – Version 2.8.9: Use Shipping with Enhanced Security

Plugin Security Certification (PSC-2024-64565): “WooCommerce Shipping & Tax” – Version 2.8.9: Use Shipping with Enhanced Security

WooCommerce Shipping & Tax is a vital extension for any WooCommerce-powered store that simplifies two of the most complex parts of running an eCommerce business: shipping and taxes. This plugin offloads critical services such as label generation and tax calculation to Automattic’s robust and secure cloud infrastructure. By doing so, it minimizes dependency on your own hosting environment, ensuring faster response times and increased platform stability.

With the ability to instantly print USPS and DHL shipping labels and automatically calculate accurate tax rates at checkout, WooCommerce Shipping & Tax is designed to save store owners time, money, and resources. The plugin has successfully passed a comprehensive security review and has been awarded the Plugin Security Certification (PSC-2025-64565) by CleanTalk, confirming its reliability and code integrity.

Plugin Security Certification (PSC-2025-64563): “Autoptimize” – Version 6.0.1: Use Optimization with Enhanced Security

Plugin Security Certification (PSC-2025-64563): “Autoptimize” – Version 6.0.1: Use Optimization with Enhanced Security

Autoptimize 3.1.13 is a high-performance optimization plugin for WordPress designed to dramatically speed up your website. By aggregating, minifying, and caching JavaScript, CSS, and HTML code, the plugin ensures leaner and faster page loads. It also enhances performance by inlining critical CSS, deferring script execution, and supporting modern image formats like WebP and AVIF. Built with flexibility and extensibility in mind, Autoptimize provides a robust API, enabling developers to fine-tune optimizations based on specific site requirements. With Autoptimize Pro, users can access premium features such as image CDN, page caching, critical CSS automation, and more.

Autoptimize has undergone rigorous code review and security testing, achieving the Plugin Security Certification (PSC-2025-64563) from CleanTalk, ensuring peace of mind for site owners and developers who prioritize security.

CVE-2025-1524 – Ultimate Dashboard < 3.8.6 – Stored XSS to Admin Creation – POC

CVE-2025-1524 – Ultimate Dashboard < 3.8.6 – Stored XSS to Admin Creation – POC

The Ultimate Dashboard plugin is a popular tool for customizing the WordPress admin dashboard, used by site owners and developers to enhance the client experience with personalized widgets, custom admin pages, and visual tweaks. However, in versions prior to 3.8.6, the plugin was affected by a Stored Cross-Site Scripting (XSS) vulnerability that could lead to privilege escalation, including unauthorized admin account creation.

This vulnerability, tracked as CVE-2025-1524, represents a critical example of how seemingly innocuous customization features can become attack vectors when proper sanitization is not enforced.

Plugin Security Certification (PSC-2025-64562): “Redux Framework” – Version 4.5.7: Use Framework with Enhanced Security

Plugin Security Certification (PSC-2025-64562): “Redux Framework” – Version 4.5.7: Use Framework with Enhanced Security

Redux Framework is a robust and developer-centric options framework for WordPress, designed to streamline and simplify theme and plugin development. Instead of reinventing the wheel with each project, Redux provides a scalable, extensible foundation for building powerful admin panels using a single, well-documented configuration file. Supporting a wide array of field types, integrated Google Fonts, compiler hooks, and validation mechanisms, Redux is a complete toolkit built for innovation.

With full responsiveness and WordPress-native integration, Redux accelerates development without compromising code quality. It enables developers to build powerful options panels faster, while also maintaining structured, secure, and maintainable code. Redux has undergone extensive security auditing and proudly holds the Plugin Security Certification (PSC-2025-64562) from CleanTalk, ensuring a secure development experience.

CVE-2025-1523 – Ultimate Dashboard < 3.8.6 – Stored XSS to Admin Creation – POC

CVE-2025-1523 – Ultimate Dashboard < 3.8.6 – Stored XSS to Admin Creation – POC

The Ultimate Dashboard plugin is a popular tool for customizing the WordPress admin dashboard, used by site owners and developers to enhance the client experience with personalized widgets, custom admin pages, and visual tweaks. However, in versions prior to 3.8.6, the plugin was affected by a Stored Cross-Site Scripting (XSS) vulnerability that could lead to privilege escalation, including unauthorized admin account creation.

This vulnerability, tracked as CVE-2025-1523, represents a critical example of how seemingly innocuous customization features can become attack vectors when proper sanitization is not enforced.