Extension WordPress
Vulnérabilités CubeWP Framework
Cette page rassemble les failles publiées pour CubeWP Framework, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de CubeWP Framework
11 fiches
CubeWP – All-in-One Dynamic Content Framework <= 1.1.27 – Unauthenticated Post Disclosure in class-cubewp-search-ajax-hooks.php
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.27 via the search feature in class-cubewp-search-ajax-hooks.php due to insufficient restrictions on which posts can be…
*-1.1.27
1.1.28
24/01/2026
CubeWP <= 1.1.26 – Authenticated (Contributor+) Stored Cross-Site Scripting via cubewp_shortcode_taxonomy Shortcode
The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cubewp_shortcode_taxonomy shortcode in all versions up to, and including, 1.1.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-1.1.26
1.1.27
16/01/2026
CubeWP – All-in-One Dynamic Content Framework <= 1.1.27 – Unauthenticated Information Exposure
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.27 via the /cubewp-posts/v1/query-new and /cubewp-posts/v1/query REST API endpoints due to insufficient restrictions on which posts…
*-1.1.27
1.1.28
16/01/2026
CubeWP <= 1.1.27 – Missing Authorization
The CubeWP Framework plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.27. This makes it possible for unauthenticated attackers to perform an…
*-1.1.27
1.1.28
26/12/2025
CubeWP <= 1.1.26 – Authenticated (Contributor+) Stored Cross-Site Scripting
The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-1.1.26
1.1.27
22/09/2025
CubeWP Framework <= 1.1.24 – Authenticated (Subscriber+) Privilege Escalation
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.24. This is due to the plugin not properly restricting user meta key updates through the…
*-1.1.24
1.1.25
19/08/2025
CubeWP Framework <= 1.1.23 – Authenticated (Contributor+) Stored Cross-Site Scripting
The CubeWP Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-1.1.23
1.1.24
12/06/2025
CubeWP – All-in-One Dynamic Content Framework <= 1.1.23 – Authenticated (Subscriber+) Privilege Escalation
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is due to the plugin allowing a user to update arbitrary user meta through…
*-1.1.23
1.1.24
10/06/2025
CubeWP – All-in-One Dynamic Content Framework <= 1.1.24 – Cross-Site Request Forgery
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24. This is due to missing or incorrect nonce validation on a function. This makes…
*-1.1.24
Non indiqué
05/06/2025
CubeWP – All-in-One Dynamic Content Framework <= 1.1.15 – Missing Authorization
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several funcstions like 'cwp_user_fields_data_callback ' and 'cwpform_save_shortcode' in versions up to, and including, 1.1.15. This makes…
*-1.1.15
1.1.16
09/10/2024
CubeWP – All-in-One Dynamic Content Framework <= 1.1.12 – Authenticated (Subscriber+) Arbitrary File Upload
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cwp_import_data_callback() function in all versions up to, and including, 1.1.12. This makes it possible…
*-1.1.12
1.1.13
28/03/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.