CVE-2024-48039
The CubeWP – All-in-One Dynamic Content Framework plugin contains an authorization flaw affecting versions through 1.1.15 where multiple functions including 'cwp_user_fields_data_callback' and 'cwpform_save_shortcode' fail to verify user permissions before execution. Authenticated users with subscriber-level permissions or higher can exploit this weakness to modify plugin configuration and download exported information. The vulnerability was patched in version 1.1.16.
Based on public CVE data (MITRE/NVD).