Qodeinteractive develops a focused line of WordPress plugins and themes for page builders and content management, including products such as QI Addons for Elementor, QI Blocks, and Backpack Traveler that extend WordPress editing and publishing capabilities. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the web-application and file-handling attack surface inherent to server-side PHP plugins. The exposure recurs across the product portfolio through weakness classes including PHP remote file inclusion, cross-site scripting, path traversal, authorization bypass, and cross-site request forgery—a pattern characteristic of plugin ecosystems where input validation, access control, and CSRF protections are inconsistently implemented. Defenders should treat WordPress sites using these plugins as high-priority for patching and should implement additional input validation and access-control hardening at the application layer. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qodeinteractive over time
Signals from CVEs in this vendor scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67515CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër wilmer allows PHP Local File Inclusion | Dec 9, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-39466CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This | Nov 6, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-39467CRITICAL Path Traversal: '.../...//' vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This issue affects Wanderland: from n/a through <= 1.7.1. | Nov 6, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-66532HIGH Missing Authorization vulnerability in Mikado-Themes Powerlift powerlift allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Powerlift: from | Dec 9, 2025 | 8.8 | 27 | NO | NO |
CVE-2026-10096MEDIUM The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.9 via the 'page_id' parameter due to missing validati | Jul 1, 2026 | 4.3 | 26 | NO | NO |
CVE-2025-67937HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Hendon hendon allows PHP Local File Inclusion | Jan 8, 2026 | 8.1 | 26 | NO | NO |
CVE-2025-67936HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly curly allows PHP Local File Inclusion.T | Jan 8, 2026 | 8.1 | 26 | NO | NO |
CVE-2025-67935HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimizewp allows PHP Local File Inc | Jan 8, 2026 | 8.1 | 26 | NO | NO |
CVE-2025-67934HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wellspring wellspring allows PHP Local File I | Jan 8, 2026 | 8.1 | 26 | NO | NO |
CVE-2025-49296CRITICAL Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issue affects GrandPrix: from n/a through <= 1.6. | Jun 9, 2025 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (41 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qodeinteractive.
Media articles that mention a CVE ID that affects a product developed by Qodeinteractive — matched by CVE ID, not by vendor name.