← WordPress Vulnerabilities
WordPress security by component

Qi Blocks

Qi Blocks is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Jul 01, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: qi-blocks

CVE-2026-10096: Qi Blocks: A security weakness

Qi Blocks is affected by a security weakness. Exploitation requires at least author-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.4.9.

PublishedJul 01, 2026
Known safe version> 1.4.9
Safe version
Jul 01, 2026 CVE-2026-10096
Qi Blocks: A security weakness
Qi Blocks is affected by a security weakness. Exploitation requires at least author-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.4.9.
> 1.4.9
CVE4.3
NVDPending
Nov 15, 2025 CVE-2025-12182
Qi Blocks: A security weakness
Qi Blocks is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Nov 13, 2025 CVE-2025-64383
Qi Blocks: Cross-site scripting
Qi Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Nov 01, 2025 CVE-2025-12180
Qi Blocks: A security weakness
Qi Blocks is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
May 19, 2025 CVE-2025-1627
Qi Blocks: Cross-site scripting
Qi Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
May 19, 2025 CVE-2025-1626
Qi Blocks: Cross-site scripting
Qi Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
May 19, 2025 CVE-2025-1625
Qi Blocks: Cross-site scripting
Qi Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Oct 23, 2024 CVE-2024-49690
Qi Blocks: A security weakness
Qi Blocks is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD8.8
Jul 20, 2024 CVE-2024-38712
Qi Blocks: Cross-site scripting
Qi Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 06, 2024 CVE-2024-5221
Qi Blocks: Cross-site scripting
Qi Blocks is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4