Extension WordPress

Vulnérabilités CubeWP Framework

Cette page rassemble les failles publiées pour CubeWP Framework, leurs plages de versions affectées et les correctifs signalés dans la base locale.

11Vulnérabilités
1Critiques
10Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de CubeWP Framework

11 fiches

CVE-2025-6461 Moyenne · 4,3
CubeWP Framework

CubeWP – All-in-One Dynamic Content Framework <= 1.1.27 – Unauthenticated Post Disclosure in class-cubewp-search-ajax-hooks.php

The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.27 via the search feature in class-cubewp-search-ajax-hooks.php due to insufficient restrictions on which posts can be…

Versions affectées

*-1.1.27

Correctif

1.1.28

Publication

24/01/2026

CVE-2025-8615 Moyenne · 6,4
CubeWP Framework

CubeWP <= 1.1.26 – Authenticated (Contributor+) Stored Cross-Site Scripting via cubewp_shortcode_taxonomy Shortcode

The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cubewp_shortcode_taxonomy shortcode in all versions up to, and including, 1.1.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

Versions affectées

*-1.1.26

Correctif

1.1.27

Publication

16/01/2026

CVE-2025-12129 Moyenne · 5,3
CubeWP Framework

CubeWP – All-in-One Dynamic Content Framework <= 1.1.27 – Unauthenticated Information Exposure

The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.27 via the /cubewp-posts/v1/query-new and /cubewp-posts/v1/query REST API endpoints due to insufficient restrictions on which posts…

Versions affectées

*-1.1.27

Correctif

1.1.28

Publication

16/01/2026

CVE-2025-49882 Moyenne · 6,4
CubeWP Framework

CubeWP Framework <= 1.1.23 – Authenticated (Contributor+) Stored Cross-Site Scripting

The CubeWP Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-1.1.23

Correctif

1.1.24

Publication

12/06/2025

CVE-2024-48039 Moyenne · 5,4
CubeWP Framework

CubeWP – All-in-One Dynamic Content Framework <= 1.1.15 – Missing Authorization

The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several funcstions like 'cwp_user_fields_data_callback ' and 'cwpform_save_shortcode' in versions up to, and including, 1.1.15. This makes…

Versions affectées

*-1.1.15

Correctif

1.1.16

Publication

09/10/2024

CVE-2024-30500 Critique · 9,9
CubeWP Framework

CubeWP – All-in-One Dynamic Content Framework <= 1.1.12 – Authenticated (Subscriber+) Arbitrary File Upload

The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cwp_import_data_callback() function in all versions up to, and including, 1.1.12. This makes it possible…

Versions affectées

*-1.1.12

Correctif

1.1.13

Publication

28/03/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités