CVE · Medium

CVE-2025-12129 — CubeWP Framework [cubewp-framework] < 1.1.28

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12129 CubeWP Framework [cubewp-framework] < 1.1.28 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 1.1.28 1.1.28 2026-01-16

CVE-2025-12129

The CubeWP plugin for WordPress has a security flaw that allows unauthorized access to sensitive post data. Specifically, attackers can use the plugin's REST API endpoints to retrieve information from posts that are password protected, private, or in draft status, even if they shouldn't have access to those posts. This vulnerability affects all versions of the plugin up to and including 1.1.27. As a result, unauthenticated attackers can extract sensitive data that was intended to be restricted.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.