Qubely – Advanced Gutenberg Blocks <= 1.8.14 - Missing Authorization
medium
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.8.14. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.8.14
- Fix:
- No patched version reported
- Disclosed:
- Jul 23, 2026
CVE-2026-65531 on NVD →
Qubely <= 1.8.14 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Qubely plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will exe...
- CVSS:
- 6.4
- Affected:
- up to 1.8.14
- Fix:
- No patched version reported
- Disclosed:
- Feb 14, 2026
CVE-2026-39638 on NVD →
Qubely <= 1.8.14 - Missing Authorization
medium
The Qubely plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.8.14. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 5.4
- Affected:
- up to 1.8.14
- Fix:
- No patched version reported
- Disclosed:
- Sep 22, 2025
CVE-2025-58663 on NVD →
Qubely <= 1.8.14 - Authenticated (Contributor+) Sensitive Information Exposure
medium
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.14. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 1.8.14
- Fix:
- No patched version reported
- Disclosed:
- Sep 22, 2025
CVE-2025-58249 on NVD →
Qubely – Advanced Gutenberg Blocks [qubely] < 1.8.14
unknown
[en] The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending,...
- Affected:
- up to 1.8.14
- Fixed in:
- 1.8.14
- Disclosed:
- Mar 11, 2025
CVE-2024-13228 on NVD →
Qubely – Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_content
medium
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, sched...
- CVSS:
- 4.3
- Affected:
- up to 1.8.13
- Fixed in:
- 1.8.14
- Disclosed:
- Mar 10, 2025
CVE-2024-13228 on NVD →
Qubely – Advanced Gutenberg Blocks [qubely] < 1.8.13
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely – Advanced Gutenberg Blocks allows Stored XSS. This issue affects Qubely – Advanced Gutenberg Blocks: from n/a through 1.8.12.
- Affected:
- up to 1.8.13
- Fixed in:
- 1.8.13
- Disclosed:
- Feb 16, 2025
CVE-2025-26767 on NVD →
Qubely <= 1.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Qubely plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 1.8.12
- Fixed in:
- 1.8.13
- Disclosed:
- Feb 14, 2025
CVE-2025-26767 on NVD →
Qubely – Advanced Gutenberg Blocks <= 1.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' and 'UniqueID'
medium
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ and 'UniqueID' parameter in all versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor...
- CVSS:
- 6.5
- Affected:
- up to 1.8.12
- Fixed in:
- 1.8.13
- Disclosed:
- Feb 13, 2025
CVE-2024-9601 on NVD →
Qubely – Advanced Gutenberg Blocks [qubely] < 1.8.5
unknown
[en] The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.5
- Disclosed:
- Jan 16, 2024
CVE-2023-0376 on NVD →
Qubely – Advanced Gutenberg Blocks [qubely] < 1.8.6
unknown
[en] The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Aug 7, 2023
CVE-2021-24916 on NVD →
Qubely – Advanced Gutenberg Blocks <= 1.8.5 - Insufficient Authorization
medium
The Qubely plugin for WordPress is vulnerable to unauthorized arbitrary e-mail sending in versions up to, and including, 1.8.5. This is due to insufficient validation on the presence of a contact form block and validation on the email fields in the qubely_send_form_data() function called via an AJAX action. This makes...
- CVSS:
- 5.3
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Jul 17, 2023
CVE-2021-24916 on NVD →
Qubely – Advanced Gutenberg Blocks [qubely] < 1.8.5
unknown
Update the WordPress Qubely – Advanced Gutenberg Blocks plugin to the latest available version (at least 1.8.5).
Wordfence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Qubely – Advanced Gutenberg Blocks Plugin. This could allow a malicious actor to inject malicious scripts, such as...
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.5
- Disclosed:
- Feb 7, 2023
Quebely <= 1.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'className' Block Option
medium
The Quebely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbi...
- CVSS:
- 6.4
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.5
- Disclosed:
- Feb 6, 2023
CVE-2023-0376 on NVD →
Qubely – Advanced Gutenberg Blocks [qubely] < 1.8.5
unknown
The Quebely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbi...
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.5
- Disclosed:
- Feb 6, 2023
Qubely <= 1.7.9 - Incorrect Authorization
medium
The Qubely plugin for WordPress contains an incorrect authorization weakness that makes it possible for contributor-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to the use of the current_user_can() function checking for the edit_posts permission available to contributo...
- CVSS:
- 5.4
- Affected:
- 1.8.0 – 1.8.0
- Fixed in:
- 1.8.1
- Disclosed:
- Jun 14, 2022
Qubely – Advanced Gutenberg Blocks [qubely] < 1.8.1
unknown
The Qubely plugin for WordPress contains an incorrect authorization weakness that makes it possible for contributor-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to the use of the current_user_can() function checking for the edit_posts permission available to contributo...
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Jun 14, 2022
Qubely <= 1.7.8 - Missing Authorization
medium
The Qubely plugin for WordPress contains a missing authorization weakness that makes it possible for subscriber-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to missing capability checks on the ajax_update_qubely_options() function called via the wp_ajax_update_qubely_o...
- CVSS:
- 5.4
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.9
- Disclosed:
- Jun 6, 2022
Qubely – Advanced Gutenberg Blocks [qubely] < 1.7.9
unknown
The Qubely plugin for WordPress contains a missing authorization weakness that makes it possible for subscriber-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to missing capability checks on the ajax_update_qubely_options() function called via the wp_ajax_update_qubely_o...
- Affected:
- up to 1.7.9
- Fixed in:
- 1.7.9
- Disclosed:
- Jun 6, 2022
Qubely – Advanced Gutenberg Blocks [qubely] < 1.8.1
unknown
Authenticated Arbitrary Settings Update vulnerability discovered by Jan w Oleju in WordPress Qubely plugin (versions <= 1.8.0)
Update the WordPress Qubely – Advanced Gutenberg Blocks plugin to the latest available version (at least 1.8.1).
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Jun 6, 2022
Qubely – Advanced Gutenberg Blocks [qubely] < 1.7.8
unknown
[en] The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.8
- Disclosed:
- Jan 24, 2022
CVE-2021-25013 on NVD →
Qubely <= 1.7.7 - Missing Authorization to Arbitrary Post Deletion
medium
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts
- CVSS:
- 5.4
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.8
- Disclosed:
- Dec 27, 2021
CVE-2021-25013 on NVD →
Qubely – Advanced Gutenberg Blocks [qubely] < 1.8.13
unknown
- Affected:
- up to 1.8.13
- Fixed in:
- 1.8.13
CVE-2024-9601 on NVD →
Qubely – Advanced Gutenberg Blocks [qubely] < 1.8.1
unknown
The plugin does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber (in versions < 1.7.9) or contributor (in v < 1.8.1) to update them
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database