CubeWP Forms – All-in-One Form Builder [cubewp-forms] < 1.1.6
unknown
[en] Missing Authorization vulnerability in Emraan Cheema CubeWP Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CubeWP Forms: from n/a through 1.1.5.
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- Jun 17, 2025
CVE-2025-49880 on NVD →
CubeWP Forms <= 1.1.5 - Missing Authorization
medium
The CubeWP Forms – All-in-One Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.6
- Disclosed:
- Jun 12, 2025
CVE-2025-49880 on NVD →
CubeWP Forms – All-in-One Form Builder [cubewp-forms] <= 1.1.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in CubeWP CubeWP Forms – All-in-One Form Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP Forms – All-in-One Form Builder: from n/a through 1.1.5.
- Affected:
- up to 1.1.5
- Fix:
- No patched version reported
- Disclosed:
- Jan 7, 2025
CVE-2024-51651 on NVD →
CubeWP Forms – All-in-One Form Builder <= 1.1.5 - Missing Authorization
medium
The CubeWP Forms – All-in-One Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.1.5
- Fix:
- No patched version reported
- Disclosed:
- Jan 6, 2025
CVE-2024-51651 on NVD →
CubeWP Forms – All-in-One Form Builder [cubewp-forms] < 1.1.2
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CubeWP CubeWP Forms – All-in-One Form Builder allows Stored XSS.This issue affects CubeWP Forms – All-in-One Form Builder: from n/a through 1.1.1.
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- Oct 6, 2024
CVE-2024-47300 on NVD →
CubeWP Forms – All-in-One Form Builder <= 1.1.1 - Unauthenticated Stored Cross-Site Scripting
high
The CubeWP Forms – All-in-One Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will exe...
- CVSS:
- 7.2
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.2
- Disclosed:
- Sep 24, 2024
CVE-2024-47300 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database