CVE-2025-58663
Qubely – Advanced Gutenberg Blocks
Minimum safe version
1.8.14
Update to 1.8.14 or later to address 12 fixable vulnerabilities
CVE-2025-58249
CVE-2026-39638
CVE-2024-13228
Qubely – Advanced Gutenberg Blocks <= 1.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' and 'UniqueID'
CVE-2025-26767
CVE-2023-0376
WordPress Qubely – Advanced Gutenberg Blocks Plugin < 1.8.6 is vulnerable to Broken Access Control
Qubely < 1.8.1 - Authenticated Arbitrary Settings Update
WordPress Qubely – Advanced Gutenberg Blocks Plugin <= 1.8.4 is vulnerable to Cross Site Scripting (XSS)
Quebely <= 1.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'className' Block Option
Qubely <= 1.7.8 - Missing Authorization
Qubely <= 1.7.9 - Incorrect Authorization
WordPress Qubely plugin <= 1.8.0 - Authenticated Arbitrary Settings Update vulnerability
CVE-2021-25013