CubeWP Framework

Information

Software Type Plugin
Software Slug cubewp-framework (view on wordpress.org)
Software Status Active
Software Author cubewp1211
Software Website cubewp.com
Software Downloads 95,684
Software Active Installs 4,000
Software Record Last Updated July 21, 2026

11 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
CubeWP – All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Post Disclosure in class-cubewp-search-ajax-hooks.php Patched CVE-2025-6461 4.3 stealthcopter January 24, 2026
CubeWP <= 1.1.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via cubewp_shortcode_taxonomy Shortcode Patched CVE-2025-8615 6.4 zaim January 16, 2026
CubeWP – All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Information Exposure Patched CVE-2025-12129 5.3 Jonas Benjamin Friedli January 16, 2026
CubeWP <= 1.1.27 - Missing Authorization Patched CVE-2025-68036 5.3 MD ISMAIL December 26, 2025
CubeWP <= 1.1.26 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2025-59569 6.4 zaim September 22, 2025
CubeWP Framework <= 1.1.24 - Authenticated (Subscriber+) Privilege Escalation Patched CVE-2025-54735 8.8 Martino Spagnuolo August 19, 2025
CubeWP Framework <= 1.1.23 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2025-49882 6.4 Muhammad Yudha - DJ June 12, 2025
CubeWP – All-in-One Dynamic Content Framework <= 1.1.23 - Authenticated (Subscriber+) Privilege Escalation Patched CVE-2025-4315 8.8 Foxyyy June 10, 2025
CubeWP – All-in-One Dynamic Content Framework <= 1.1.24 - Cross-Site Request Forgery Unpatched CVE-2025-30994 4.3 domiee13 June 5, 2025
CubeWP – All-in-One Dynamic Content Framework <= 1.1.15 - Missing Authorization Patched CVE-2024-48039 5.4 Abdi Pranata October 9, 2024
CubeWP – All-in-One Dynamic Content Framework <= 1.1.12 - Authenticated (Subscriber+) Arbitrary File Upload Patched CVE-2024-30500 9.9 Peng Zhou March 28, 2024

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation