Medium 6.5
2025-09-22< 1.1.27
CubeWP <= 1.1.26 - Authenticated (Contributor+) Stored Cross-Site Scripting
Minimum safe version
1.1.28
Update to 1.1.28 or later to address 10 fixable vulnerabilities
CubeWP <= 1.1.26 - Authenticated (Contributor+) Stored Cross-Site Scripting
CubeWP <= 1.1.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via cubewp_shortcode_taxonomy Shortcode
CubeWP – All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Post Disclosure in class-cubewp-search-ajax-hooks.php
CVE-2025-12129
CVE-2025-68036
CVE-2025-54735
CVE-2025-49882
CubeWP – All-in-One Dynamic Content Framework <= 1.1.23 - Authenticated (Subscriber+) Privilege Escalation
WordPress CubeWP plugin <= 1.1.29 - Cross Site Request Forgery (CSRF) vulnerability
CVE-2024-48039
CVE-2024-30500