plugin

Cubewp Forms Vulnerabilities

6 known security issues reported for the Cubewp Forms WordPress plugin. Most recent disclosed Jun 17, 2025.

1 high 2 medium

Running Cubewp Forms on your site? Check whether your installed version is affected.

Scan your site free

CubeWP Forms &#8211; All-in-One Form Builder [cubewp-forms] < 1.1.6

unknown

[en] Missing Authorization vulnerability in Emraan Cheema CubeWP Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CubeWP Forms: from n/a through 1.1.5.

Affected:
up to 1.1.6
Fixed in:
1.1.6
Disclosed:
Jun 17, 2025

CVE-2025-49880 on NVD →

CubeWP Forms <= 1.1.5 - Missing Authorization

medium

The CubeWP Forms – All-in-One Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.1.5
Fixed in:
1.1.6
Disclosed:
Jun 12, 2025

CVE-2025-49880 on NVD →

CubeWP Forms &#8211; All-in-One Form Builder [cubewp-forms] <= 1.1.5 (unfixed)

unknown

[en] Missing Authorization vulnerability in CubeWP CubeWP Forms – All-in-One Form Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP Forms – All-in-One Form Builder: from n/a through 1.1.5.

Affected:
up to 1.1.5
Fix:
No patched version reported
Disclosed:
Jan 7, 2025

CVE-2024-51651 on NVD →

CubeWP Forms – All-in-One Form Builder <= 1.1.5 - Missing Authorization

medium

The CubeWP Forms – All-in-One Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.1.5
Fix:
No patched version reported
Disclosed:
Jan 6, 2025

CVE-2024-51651 on NVD →

CubeWP Forms &#8211; All-in-One Form Builder [cubewp-forms] < 1.1.2

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CubeWP CubeWP Forms – All-in-One Form Builder allows Stored XSS.This issue affects CubeWP Forms – All-in-One Form Builder: from n/a through 1.1.1.

Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
Oct 6, 2024

CVE-2024-47300 on NVD →

CubeWP Forms – All-in-One Form Builder <= 1.1.1 - Unauthenticated Stored Cross-Site Scripting

high

The CubeWP Forms – All-in-One Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will exe...

CVSS:
7.2
Affected:
up to 1.1.1
Fixed in:
1.1.2
Disclosed:
Sep 24, 2024

CVE-2024-47300 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database