PT-2026-54504 · WordPress · Qi Blocks
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Qi Blocks versions prior to 1.5.0
Description
An Insecure Direct Object Reference occurs when the plugin fails to validate a user-controlled key. Authenticated attackers with author-level access or higher can exploit this to modify stored styles of posts, templates, or widgets they do not own. By using reserved values for the
page id parameter, attackers can affect site-wide surfaces, leading to unauthorized frontend defacement, content hiding, and page degradation. The issue exists because the endpoint's permission check only verifies generic edit posts and publish posts capabilities without confirming post ownership.Recommendations
Update Qi Blocks to version 1.5.0 or later.
Restrict the use of the
page id parameter for users with author-level access until the update is applied.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qi Blocks