cleantalk
Vulnerabilities and Security Researches

Qi Blocks, CVE-2025-12180

CVE, Research URL

CVE-2025-12180

Application

Qi Blocks

Published on
Nov 01, 2025
Research Description
The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. This is due to the plugin storing arbitrary CSS styles submitted via the `qi-blocks/v1/update-styles` REST API endpoint without proper sanitization in the `update_global_styles_callback()` function. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary CSS, which can be used to perform actions such as hiding content, overlaying fake UI elements, or exfiltrating sensitive information via CSS injection techniques.
Affected versions
max 1.4.4.
Status
vulnerable