PT-2026-54504 · WordPress · Qi Blocks

·

CVE-2026-10096

·

Published

2026-07-01

·

Updated

2026-07-01

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Qi Blocks versions prior to 1.5.0
Description An Insecure Direct Object Reference occurs when the plugin fails to validate a user-controlled key. Authenticated attackers with author-level access or higher can exploit this to modify stored styles of posts, templates, or widgets they do not own. By using reserved values for the page id parameter, attackers can affect site-wide surfaces, leading to unauthorized frontend defacement, content hiding, and page degradation. The issue exists because the endpoint's permission check only verifies generic edit posts and publish posts capabilities without confirming post ownership.
Recommendations Update Qi Blocks to version 1.5.0 or later. Restrict the use of the page id parameter for users with author-level access until the update is applied.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10096

Affected Products

Qi Blocks