Unauthorized Image Resizing Vulnerability in Qi Blocks Plugin for WordPress
CVE-2025-12182
4.3MEDIUM
What is CVE-2025-12182?
The Qi Blocks plugin for WordPress is susceptible to unauthorized access due to a missing capability check in the 'resize_image_callback()' function. This vulnerability affects all versions up to and including 1.4.3. It allows attackers with Contributor-level access or higher to resize arbitrary images in the media library, potentially leading to unintended file writes and a strain on server resources from the processing of large images. Proper user permission verification is lacking, posing a significant risk to WordPress sites utilizing this plugin.
Affected Version(s)
Qi Blocks * <= 1.4.3