Extension WordPress
Vulnérabilités Qubely – Advanced Gutenberg Blocks
Cette page rassemble les failles publiées pour Qubely – Advanced Gutenberg Blocks, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Qubely – Advanced Gutenberg Blocks
11 fiches
Qubely <= 1.8.14 – Authenticated (Author+) Stored Cross-Site Scripting
The Qubely plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above,…
*-1.8.14
Non indiqué
14/02/2026
Qubely <= 1.8.14 – Authenticated (Contributor+) Sensitive Information Exposure
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.14. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive…
*-1.8.14
Non indiqué
22/09/2025
Qubely <= 1.8.14 – Missing Authorization
The Qubely plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.8.14. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-1.8.14
Non indiqué
22/09/2025
Qubely – Advanced Gutenberg Blocks <= 1.8.13 – Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_content
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for authenticated attackers, with Contributor-level access and above,…
*-1.8.13
1.8.14
10/03/2025
Qubely <= 1.8.12 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Qubely plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-1.8.12
1.8.13
14/02/2025
Qubely – Advanced Gutenberg Blocks <= 1.8.12 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' and 'UniqueID'
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ and 'UniqueID' parameter in all versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This…
*-1.8.12
1.8.13
13/02/2025
Qubely – Advanced Gutenberg Blocks <= 1.8.5 – Insufficient Authorization
The Qubely plugin for WordPress is vulnerable to unauthorized arbitrary e-mail sending in versions up to, and including, 1.8.5. This is due to insufficient validation on the presence of a contact form block and validation on the email…
[*, 1.8.6)
1.8.6
17/07/2023
Quebely <= 1.8.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'className' Block Option
The Quebely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-1.8.4
1.8.5
06/02/2023
Qubely <= 1.7.9 – Incorrect Authorization
The Qubely plugin for WordPress contains an incorrect authorization weakness that makes it possible for contributor-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to the use of the current_user_can()…
1.8.0
1.8.1
14/06/2022
Qubely <= 1.7.8 – Missing Authorization
The Qubely plugin for WordPress contains a missing authorization weakness that makes it possible for subscriber-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to missing capability checks on the…
*-1.7.8
1.7.9
06/06/2022
Qubely <= 1.7.7 – Missing Authorization to Arbitrary Post Deletion
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users,…
[*, 1.7.8)
1.7.8
27/12/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.