Impact
The vulnerability is an improper neutralization of input during web page generation that allows stored cross‑site scripting on websites using Qode Qi Blocks. The flaw permits an attacker to inject arbitrary JavaScript that will be executed whenever a user views a post or page containing the malicious payload. The injected code can exfiltrate credentials, hijack user sessions, or alter site content.
Affected Systems
The issue affects the Qode Qi Blocks plugin for WordPress, versions up to and including 1.4.3. Sites that have deployed this plugin without upgrading to a newer release are vulnerable. No other WordPress core components are impacted by this flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, consistent with the potential for widespread impact via XSS. The EPSS score is below 1 %, suggesting a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers could target the plugin’s input fields, such as custom code boxes or widget areas, to store malicious scripts. Once stored, any visitor to the affected page would execute the injected code, subjecting them to the threat described above.
OpenCVE Enrichment