PLUGIN SECURITY
Is Cubewp Framework safe?
CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.
What this plugin does
- Slug:
cubewp-framework - Author: Imran Tauqeer
- 4000+ active installs
- 96/100 rating (12 reviews on wordpress.org)
- 98917 all-time downloads
- On WordPress.org since 2022-09-30
acfcustom fieldscustom post typesCustom Taxonomiesmetabox
Maintenance status
- Latest known version: 1.1.31
- Last updated: 2026-07-29 10:58pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
16 known CVEs on file for Cubewp Framework.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-28168 | CubeWP Framework [cubewp-framework] < 1.1.31 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.5 | < 1.1.31 | 1.1.31 | 2026-08-13 | ✓ fixed in latest |
| CVE-2026-17018 | CubeWP Framework [cubewp-framework] <= 1.1.30 (unfixed) | Authorization Bypass Through User-Controlled Key | Unknown | < 1.1.30 | 1.1.30 | 2026-08-10 | ✓ fixed in latest |
| CVE-2026-17017 | CubeWP Framework [cubewp-framework] < 1.1.31 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Unknown | < 1.1.31 | 1.1.31 | 2026-08-09 | ✓ fixed in latest |
| CVE-2026-13339 | CubeWP Framework [cubewp-framework] < 1.1.31 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.5 | < 1.1.31 | 1.1.31 | 2026-08-01 | ✓ fixed in latest |
| CVE-2026-6453 | CubeWP Framework [cubewp-framework] < 1.1.31 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 1.1.31 | 1.1.31 | 2026-07-31 | ✓ fixed in latest |
| CVE-2025-12129 | CubeWP Framework [cubewp-framework] < 1.1.28 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 1.1.28 | 1.1.28 | 2026-01-16 | ✓ fixed in latest |
| CVE-2025-68036 | CubeWP Framework [cubewp-framework] < 1.1.28 | Missing Authorization | High 7.5 | < 1.1.28 | 1.1.28 | 2025-12-26 | ✓ fixed in latest |
| CVE-2025-54735 | CubeWP Framework [cubewp-framework] < 1.1.25 | Incorrect Privilege Assignment | High 8.8 | < 1.1.25 | 1.1.25 | 2025-08-19 | ✓ fixed in latest |
+ 13 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-49882 | CubeWP Framework [cubewp-framework] < 1.1.24 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 1.1.24 | 1.1.24 | 2025-06-12 | ✓ fixed in latest |
| — | CubeWP Framework [cubewp-framework] <= 1.1.31 (unfixed) | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 1.1.31 | 1.1.31 | 2025-06-05 | ✓ fixed in latest |
| CVE-2024-48039 | CubeWP Framework [cubewp-framework] < 1.1.16 | Missing Authorization | Medium 4.3 | < 1.1.16 | 1.1.16 | 2024-10-09 | ✓ fixed in latest |
| CVE-2024-30500 | CubeWP Framework [cubewp-framework] < 1.1.13 | Unrestricted Upload of File with Dangerous Type | High 8.8 | < 1.1.13 | 1.1.13 | 2024-03-28 | ✓ fixed in latest |
| — | CubeWP Framework [cubewp-framework] < 1.1.24 | Improper Privilege Management | High 8.8 | < 1.1.24 | 1.1.24 | 0000-00-00 | ✓ fixed in latest |
| — | CubeWP Framework [cubewp-framework] < 1.1.28 | — | Medium 4.3 | < 1.1.28 | 1.1.28 | 0000-00-00 | ✓ fixed in latest |
| — | CubeWP Framework [cubewp-framework] < 1.1.27 | — | Medium 6.4 | < 1.1.27 | 1.1.27 | 0000-00-00 | ✓ fixed in latest |
| — | CubeWP Framework [cubewp-framework] < 1.1.27 | — | Medium 6.5 | < 1.1.27 | 1.1.27 | 0000-00-00 | ✓ fixed in latest |
| CVE-2025-4315 | CubeWP – All-in-One Dynamic Content Framework < 1.1.24 - Authenticated (Subscriber+) Privilege Escalation | — | Unknown | < 1.1.24 | 1.1.24 | — | ✓ fixed in latest |
| CVE-2025-30994 | CubeWP <= 1.1.29 - Cross-Site Request Forgery | — | Unknown | not specified | no fix on file | — | — |
| CVE-2025-59569 | CubeWP < 1.1.27 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | < 1.1.27 | 1.1.27 | — | ✓ fixed in latest |
| CVE-2025-8615 | CubeWP < 1.1.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via cubewp_shortcode_taxonomy Shortcode | — | Unknown | < 1.1.27 | 1.1.27 | — | ✓ fixed in latest |
| CVE-2025-6461 | CubeWP – All-in-One Dynamic Content Framework < 1.1.28 - Unauthenticated Post Disclosure in class-cubewp-search-ajax-hooks.php | — | Unknown | < 1.1.28 | 1.1.28 | — | ✓ fixed in latest |
How to fix it
Keep Cubewp Framework updated — 1.1.31 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
1 of the vulnerabilities above has no fixed version on file — there's no update that resolves it. Consider deactivating this plugin or switching to one of the alternatives below.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Advanced Custom Fields (ACF®) — 2000000+ active installs — 90/100 (1438) — max PHP 8.4
- Meta Box — 500000+ active installs — 96/100 (165) — max PHP 8.4
- Checkout Field Editor (Checkout Manager) for WooCommerce — 400000+ active installs — 98/100 (1056) — max PHP 8.4
- ACF Content Analysis for Yoast SEO — 100000+ active installs — 82/100 (35) — max PHP 8.4
- Advanced Custom Fields: Extended — 100000+ active installs — 96/100 (132) — max PHP <8.0
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.