Qubely – Advanced Gutenberg Blocks

Information

Software Type Plugin
Software Slug qubely (view on wordpress.org)
Software Status Active
Software Author themeum
Software Website www.themeum.com
Software Downloads 523,715
Software Active Installs 7,000
Software Record Last Updated August 8, 2026

12 Vulnerabilities

5.4
CVE ID Unknown
Jun 14, 2022
Researcher: Jan w Oleju
5.4
CVE ID Unknown
Jun 6, 2022
Researcher: Jan w Oleju
Title Status CVE ID CVSS Researchers Date
Qubely – Advanced Gutenberg Blocks <= 1.8.14 - Missing Authorization Unpatched CVE-2026-65531 5.3 Ananda Dhakal July 23, 2026
Qubely <= 1.8.14 - Authenticated (Author+) Stored Cross-Site Scripting Unpatched CVE-2026-39638 6.4 Athiwat Tiprasaharn (Jitlada) February 14, 2026
Qubely <= 1.8.14 - Missing Authorization Unpatched CVE-2025-58663 5.4 Denver Jackson September 22, 2025
Qubely <= 1.8.14 - Authenticated (Contributor+) Sensitive Information Exposure Unpatched CVE-2025-58249 4.3 Abu Hurayra (HurayraIIT) September 22, 2025
Qubely – Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_content Patched CVE-2024-13228 4.3 Nishiv March 10, 2025
Qubely <= 1.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2025-26767 6.4 zaim February 14, 2025
Qubely – Advanced Gutenberg Blocks <= 1.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' and 'UniqueID' Patched CVE-2024-9601 6.5 Nishiv February 13, 2025
Qubely – Advanced Gutenberg Blocks <= 1.8.5 - Insufficient Authorization Patched CVE-2021-24916 5.3 Krzysztof Zając July 17, 2023
Quebely <= 1.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'className' Block Option Patched CVE-2023-0376 6.4 István Márton February 6, 2023
Qubely <= 1.7.9 - Incorrect Authorization Patched 5.4 Jan w Oleju June 14, 2022
Qubely <= 1.7.8 - Missing Authorization Patched 5.4 Jan w Oleju June 6, 2022
Qubely <= 1.7.7 - Missing Authorization to Arbitrary Post Deletion Patched CVE-2021-25013 5.4 Krzysztof Zając December 27, 2021

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation