plugin

Qubely Vulnerabilities

24 known security issues reported for the Qubely WordPress plugin. Most recent disclosed Jul 23, 2026.

12 medium

Running Qubely on your site? Check whether your installed version is affected.

Scan your site free

Qubely – Advanced Gutenberg Blocks <= 1.8.14 - Missing Authorization

medium

The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.8.14. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.8.14
Fix:
No patched version reported
Disclosed:
Jul 23, 2026

CVE-2026-65531 on NVD →

Qubely <= 1.8.14 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Qubely plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will exe...

CVSS:
6.4
Affected:
up to 1.8.14
Fix:
No patched version reported
Disclosed:
Feb 14, 2026

CVE-2026-39638 on NVD →

Qubely <= 1.8.14 - Missing Authorization

medium

The Qubely plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.8.14. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

CVSS:
5.4
Affected:
up to 1.8.14
Fix:
No patched version reported
Disclosed:
Sep 22, 2025

CVE-2025-58663 on NVD →

Qubely <= 1.8.14 - Authenticated (Contributor+) Sensitive Information Exposure

medium

The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.14. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 1.8.14
Fix:
No patched version reported
Disclosed:
Sep 22, 2025

CVE-2025-58249 on NVD →

Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.8.14

unknown

[en] The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending,...

Affected:
up to 1.8.14
Fixed in:
1.8.14
Disclosed:
Mar 11, 2025

CVE-2024-13228 on NVD →

Qubely – Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_content

medium

The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, sched...

CVSS:
4.3
Affected:
up to 1.8.13
Fixed in:
1.8.14
Disclosed:
Mar 10, 2025

CVE-2024-13228 on NVD →

Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.8.13

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely – Advanced Gutenberg Blocks allows Stored XSS. This issue affects Qubely – Advanced Gutenberg Blocks: from n/a through 1.8.12.

Affected:
up to 1.8.13
Fixed in:
1.8.13
Disclosed:
Feb 16, 2025

CVE-2025-26767 on NVD →

Qubely <= 1.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Qubely plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil...

CVSS:
6.4
Affected:
up to 1.8.12
Fixed in:
1.8.13
Disclosed:
Feb 14, 2025

CVE-2025-26767 on NVD →

Qubely – Advanced Gutenberg Blocks <= 1.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' and 'UniqueID'

medium

The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ and 'UniqueID' parameter in all versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor...

CVSS:
6.5
Affected:
up to 1.8.12
Fixed in:
1.8.13
Disclosed:
Feb 13, 2025

CVE-2024-9601 on NVD →

Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.8.5

unknown

[en] The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 1.8.5
Fixed in:
1.8.5
Disclosed:
Jan 16, 2024

CVE-2023-0376 on NVD →

Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.8.6

unknown

[en] The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.

Affected:
up to 1.8.6
Fixed in:
1.8.6
Disclosed:
Aug 7, 2023

CVE-2021-24916 on NVD →

Qubely – Advanced Gutenberg Blocks <= 1.8.5 - Insufficient Authorization

medium

The Qubely plugin for WordPress is vulnerable to unauthorized arbitrary e-mail sending in versions up to, and including, 1.8.5. This is due to insufficient validation on the presence of a contact form block and validation on the email fields in the qubely_send_form_data() function called via an AJAX action. This makes...

CVSS:
5.3
Affected:
up to 1.8.6
Fixed in:
1.8.6
Disclosed:
Jul 17, 2023

CVE-2021-24916 on NVD →

Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.8.5

unknown

Update the WordPress Qubely – Advanced Gutenberg Blocks plugin to the latest available version (at least 1.8.5). Wordfence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Qubely – Advanced Gutenberg Blocks Plugin. This could allow a malicious actor to inject malicious scripts, such as...

Affected:
up to 1.8.5
Fixed in:
1.8.5
Disclosed:
Feb 7, 2023

Quebely <= 1.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'className' Block Option

medium

The Quebely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbi...

CVSS:
6.4
Affected:
up to 1.8.4
Fixed in:
1.8.5
Disclosed:
Feb 6, 2023

CVE-2023-0376 on NVD →

Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.8.5

unknown

The Quebely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbi...

Affected:
up to 1.8.5
Fixed in:
1.8.5
Disclosed:
Feb 6, 2023

Qubely <= 1.7.9 - Incorrect Authorization

medium

The Qubely plugin for WordPress contains an incorrect authorization weakness that makes it possible for contributor-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to the use of the current_user_can() function checking for the edit_posts permission available to contributo...

CVSS:
5.4
Affected:
1.8.0 – 1.8.0
Fixed in:
1.8.1
Disclosed:
Jun 14, 2022

Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.8.1

unknown

The Qubely plugin for WordPress contains an incorrect authorization weakness that makes it possible for contributor-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to the use of the current_user_can() function checking for the edit_posts permission available to contributo...

Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Jun 14, 2022

Qubely <= 1.7.8 - Missing Authorization

medium

The Qubely plugin for WordPress contains a missing authorization weakness that makes it possible for subscriber-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to missing capability checks on the ajax_update_qubely_options() function called via the wp_ajax_update_qubely_o...

CVSS:
5.4
Affected:
up to 1.7.8
Fixed in:
1.7.9
Disclosed:
Jun 6, 2022

Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.7.9

unknown

The Qubely plugin for WordPress contains a missing authorization weakness that makes it possible for subscriber-level users to update the plugin's settings in versions up to, and including 1.7.8. This is due to missing capability checks on the ajax_update_qubely_options() function called via the wp_ajax_update_qubely_o...

Affected:
up to 1.7.9
Fixed in:
1.7.9
Disclosed:
Jun 6, 2022

Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.8.1

unknown

Authenticated Arbitrary Settings Update vulnerability discovered by Jan w Oleju in WordPress Qubely plugin (versions <= 1.8.0) Update the WordPress Qubely – Advanced Gutenberg Blocks plugin to the latest available version (at least 1.8.1).

Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Jun 6, 2022

Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.7.8

unknown

[en] The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts

Affected:
up to 1.7.8
Fixed in:
1.7.8
Disclosed:
Jan 24, 2022

CVE-2021-25013 on NVD →

Qubely <= 1.7.7 - Missing Authorization to Arbitrary Post Deletion

medium

The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts

CVSS:
5.4
Affected:
up to 1.7.8
Fixed in:
1.7.8
Disclosed:
Dec 27, 2021

CVE-2021-25013 on NVD →

Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.8.13

unknown
Affected:
up to 1.8.13
Fixed in:
1.8.13

CVE-2024-9601 on NVD →

Qubely &#8211; Advanced Gutenberg Blocks [qubely] < 1.8.1

unknown

The plugin does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber (in versions &lt; 1.7.9) or contributor (in v &lt; 1.8.1) to update them

Affected:
up to 1.8.1
Fixed in:
1.8.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database