---
id: CVE-2025-12182
title: >-
  The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to
  a missing capability check on the `resize_image_callback()` function in all
  versions up to, and including, 1.4.3
summary: >-
  The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to
  a missing capability check on the `resize_image_callback()` function in all
  versions up to, and including, 1.4.3. This is due to the plugin not properly
  verif…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-284
published: '2025-11-15'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12182'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/qi-blocks/tags/1.4.3/inc/media/class-qi-blocks-media.php#L138
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset/3387712/qi-blocks/trunk/inc/media/class-qi-blocks-media.php
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/41b0b12f-ff52-4913-aa54-3fbaf0839959?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00219
epssPercentile: 0.11282
ingestedAt: '2026-10-07T21:54:15.044Z'
---

## Overview

The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up to, and including, 1.4.3. This is due to the plugin not properly verifying that a user has permission to resize a specific attachment. This makes it possible for authenticated attackers, with Contributor-level access and above, to resize arbitrary media library images belonging to other users, which can result in unintended file writes, disk consumption, and server resource abuse through processing of large images.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
