Resources /
WordPress Plugins /
Hub Core
PLUGIN SECURITY
Is Hub Core safe?
Known vulnerabilities, PHP compatibility and safer alternatives for the Hub Core WordPress plugin — checked against WP Clinic's local security database.
What this plugin does
Maintenance status
Known vulnerabilities
1 known CVE on file for Hub Core.
Reported between 2025 and 2025.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-68065
|
Hub Core [hub-core] <= 5.0.8 (unfixed) |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') |
High
7.5
|
< 5.0.8
|
5.0.8 |
2025-11-09 |
—
|
CVE-2025-68065
The Hub Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.0.8. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.
Source:
Wordfence
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.