Cubewp is a focused WordPress plugin vendor whose vulnerability exposure centers on privilege-management and file-upload handling within its plugin product. The recurring weakness classes—improper privilege management, missing authorization, and unrestricted file uploads—reflect the characteristic security boundaries in WordPress plugin architecture where access control and input validation at the application layer are critical. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cubewp over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-48039HIGH Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP: from | Nov 1, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-30500HIGH Unrestricted Upload of File with Dangerous Type vulnerability in CubeWP CubeWP – All-in-One Dynamic Content Framework.This issue affects CubeWP – All-in-One Dynamic Content Framewo | Mar 29, 2024 | 8.8 | 23 | NO | NO |
CVE-2025-4315HIGH The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is due to the plugin | Jun 11, 2025 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cubewp.
Media articles that mention a CVE ID that affects a product developed by Cubewp — matched by CVE ID, not by vendor name.