PLUGIN SECURITY

Is Cubewp Framework safe?

CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.

What this plugin does

  • Slug: cubewp-framework
  • Author: Imran Tauqeer
  • 4000+ active installs
  • 96/100 rating (12 reviews on wordpress.org)
  • 98917 all-time downloads
  • On WordPress.org since 2022-09-30

acfcustom fieldscustom post typesCustom Taxonomiesmetabox

Maintenance status

  • Latest known version: 1.1.31
  • Last updated: 2026-07-29 10:58pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

16 known CVEs on file for Cubewp Framework.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-28168 CubeWP Framework [cubewp-framework] < 1.1.31 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.5 < 1.1.31 1.1.31 2026-08-13 ✓ fixed in latest
CVE-2026-17018 CubeWP Framework [cubewp-framework] <= 1.1.30 (unfixed) Authorization Bypass Through User-Controlled Key Unknown < 1.1.30 1.1.30 2026-08-10 ✓ fixed in latest
CVE-2026-17017 CubeWP Framework [cubewp-framework] < 1.1.31 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 1.1.31 1.1.31 2026-08-09 ✓ fixed in latest
CVE-2026-13339 CubeWP Framework [cubewp-framework] < 1.1.31 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.5 < 1.1.31 1.1.31 2026-08-01 ✓ fixed in latest
CVE-2026-6453 CubeWP Framework [cubewp-framework] < 1.1.31 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 6.5 < 1.1.31 1.1.31 2026-07-31 ✓ fixed in latest
CVE-2025-12129 CubeWP Framework [cubewp-framework] < 1.1.28 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 1.1.28 1.1.28 2026-01-16 ✓ fixed in latest
CVE-2025-68036 CubeWP Framework [cubewp-framework] < 1.1.28 Missing Authorization High 7.5 < 1.1.28 1.1.28 2025-12-26 ✓ fixed in latest
CVE-2025-54735 CubeWP Framework [cubewp-framework] < 1.1.25 Incorrect Privilege Assignment High 8.8 < 1.1.25 1.1.25 2025-08-19 ✓ fixed in latest
+ 13 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-49882 CubeWP Framework [cubewp-framework] < 1.1.24 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 1.1.24 1.1.24 2025-06-12 ✓ fixed in latest
CubeWP Framework [cubewp-framework] <= 1.1.31 (unfixed) Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.1.31 1.1.31 2025-06-05 ✓ fixed in latest
CVE-2024-48039 CubeWP Framework [cubewp-framework] < 1.1.16 Missing Authorization Medium 4.3 < 1.1.16 1.1.16 2024-10-09 ✓ fixed in latest
CVE-2024-30500 CubeWP Framework [cubewp-framework] < 1.1.13 Unrestricted Upload of File with Dangerous Type High 8.8 < 1.1.13 1.1.13 2024-03-28 ✓ fixed in latest
CubeWP Framework [cubewp-framework] < 1.1.24 Improper Privilege Management High 8.8 < 1.1.24 1.1.24 0000-00-00 ✓ fixed in latest
CubeWP Framework [cubewp-framework] < 1.1.28 Medium 4.3 < 1.1.28 1.1.28 0000-00-00 ✓ fixed in latest
CubeWP Framework [cubewp-framework] < 1.1.27 Medium 6.4 < 1.1.27 1.1.27 0000-00-00 ✓ fixed in latest
CubeWP Framework [cubewp-framework] < 1.1.27 Medium 6.5 < 1.1.27 1.1.27 0000-00-00 ✓ fixed in latest
CVE-2025-4315 CubeWP – All-in-One Dynamic Content Framework < 1.1.24 - Authenticated (Subscriber+) Privilege Escalation Unknown < 1.1.24 1.1.24 ✓ fixed in latest
CVE-2025-30994 CubeWP <= 1.1.29 - Cross-Site Request Forgery Unknown not specified no fix on file
CVE-2025-59569 CubeWP < 1.1.27 - Authenticated (Contributor+) Stored Cross-Site Scripting Unknown < 1.1.27 1.1.27 ✓ fixed in latest
CVE-2025-8615 CubeWP < 1.1.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via cubewp_shortcode_taxonomy Shortcode Unknown < 1.1.27 1.1.27 ✓ fixed in latest
CVE-2025-6461 CubeWP – All-in-One Dynamic Content Framework < 1.1.28 - Unauthenticated Post Disclosure in class-cubewp-search-ajax-hooks.php Unknown < 1.1.28 1.1.28 ✓ fixed in latest

How to fix it

Keep Cubewp Framework updated — 1.1.31 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

1 of the vulnerabilities above has no fixed version on file — there's no update that resolves it. Consider deactivating this plugin or switching to one of the alternatives below.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.