CVE-2025-12129
The CubeWP plugin for WordPress has a security flaw that allows unauthorized access to sensitive post data. Specifically, attackers can use the plugin's REST API endpoints to retrieve information from posts that are password protected, private, or in draft status, even if they shouldn't have access to those posts. This vulnerability affects all versions of the plugin up to and including 1.1.27. As a result, unauthenticated attackers can extract sensitive data that was intended to be restricted.
Based on public CVE data (MITRE/NVD).