CVE-2025-64383 Overview
CVE-2025-64383 is a stored cross-site scripting (XSS) vulnerability in the Qode Qi Blocks WordPress plugin. The flaw affects all versions of qi-blocks up to and including 1.4.3. Authenticated attackers with low privileges can inject malicious scripts that persist in the database and execute in the browsers of other users who view affected pages.
The vulnerability is classified under CWE-79, improper neutralization of input during web page generation. The scope changes at execution time, meaning the injected payload can affect resources beyond the vulnerable component.
Critical Impact
Attackers with contributor-level access or higher can store JavaScript payloads that execute against site administrators, enabling session theft, privilege escalation, and site takeover through administrative actions.
Affected Products
- Qode Qi Blocks WordPress plugin (qi-blocks)
- All versions from initial release through 1.4.3
- WordPress sites with the plugin activated and user roles able to publish content
Discovery Timeline
- 2025-11-13 - CVE-2025-64383 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-64383
Vulnerability Analysis
The Qi Blocks plugin fails to sanitize and encode user-supplied input before rendering it within page markup generated by the plugin's blocks. An authenticated user with content submission rights can craft block attributes or content fields that include HTML or JavaScript payloads. The plugin stores this input in the WordPress database and later reflects it into rendered pages without adequate escaping.
Because the payload persists server-side, every visitor who loads the affected page executes the attacker's script in their session. The Patchstack advisory confirms the stored XSS behavior and version range. See the Patchstack XSS Vulnerability Report for the vendor coordination record.
Root Cause
The root cause is missing or insufficient output encoding within the plugin's block rendering logic. WordPress provides escaping helpers such as esc_html(), esc_attr(), and wp_kses_post(), but the affected code paths in qi-blocks versions 1.4.3 and earlier do not consistently apply these to attacker-controlled block attributes.
Attack Vector
Exploitation requires a network-reachable WordPress site, an authenticated account with content-editing privileges, and user interaction from a victim who loads the poisoned page. The attacker submits a Qi Block containing a JavaScript payload embedded in a supported attribute. When an administrator previews or reviews the content, the script executes with the administrator's browser context, allowing cookie theft, CSRF against admin endpoints, or plugin installation.
No verified proof-of-concept code is published in the enriched data. The vulnerability mechanism is described in the linked Patchstack advisory.
Detection Methods for CVE-2025-64383
Indicators of Compromise
- Post or page content in wp_posts containing <script> tags, on* event handlers, or javascript: URIs inside Qi Blocks markup
- Unexpected outbound requests from administrator browsers to attacker-controlled domains after viewing user-submitted content
- New administrator accounts or plugin installations following content review sessions
Detection Strategies
- Scan wp_posts.post_content for Qi Block shortcodes or block comments containing script tags or event handler attributes
- Deploy a web application firewall rule that inspects POST requests to /wp-json/wp/v2/ and /wp-admin/post.php for XSS payloads targeting Qi Block attributes
- Review the plugin version through wp plugin list --name=qi-blocks and flag any installation at or below 1.4.3
Monitoring Recommendations
- Enable WordPress audit logging for post creation and update events by non-administrator roles
- Monitor administrator sessions for anomalous XHR requests originating from post preview or edit screens
- Alert on plugin, theme, or user account changes that occur within minutes of content review activity
How to Mitigate CVE-2025-64383
Immediate Actions Required
- Deactivate the Qi Blocks plugin on affected WordPress sites until a patched version is installed
- Audit existing posts and pages authored by non-administrator accounts for embedded scripts within Qi Block content
- Restrict content-editing capabilities to trusted users and enforce multi-factor authentication on all accounts with publishing rights
Patch Information
At the time of publication, the enriched data lists affected versions through 1.4.3 with no fixed version identified. Monitor the Patchstack advisory and the plugin's WordPress.org listing for a security release, and apply it immediately once available.
Workarounds
- Remove the plugin entirely if it is not business-critical and replace it with a maintained block library
- Deploy a WAF rule that blocks HTML tag characters in Qi Block attribute parameters submitted through the REST API and admin post endpoints
- Apply a Content Security Policy that disallows inline scripts on the WordPress front end and admin dashboard to reduce payload execution
# Configuration example: disable the plugin via WP-CLI pending a patch
wp plugin deactivate qi-blocks
wp plugin status qi-blocks
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.