WordPress security by component
Qubely
Plugin description
Qubely is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 7.5.
Plugin slug:
qubelyLatest vulnerability
CVE-2026-65531: Qubely: A security weakness
Qubely is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.8.14.
| Safe version |
|
||
|---|---|---|---|
| Jul 23, 2026 |
CVE-2026-65531
Qubely: A security weakness
Qubely is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.8.14.
|
> 1.8.14 |
CVE4.8
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39638
Qubely: Cross-site scripting
Qubely is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.8.14.
|
> 1.8.14 |
CVE5.9
NVDPending
|
| Sep 22, 2025 |
CVE-2025-58663
Qubely: A security weakness
Qubely is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 22, 2025 |
CVE-2025-58249
Qubely: A security weakness
Qubely is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 11, 2025 |
CVE-2024-13228
Qubely – Advanced Gutenberg Blocks: Sensitive information exposure
Qubely – Advanced Gutenberg Blocks is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE4.3
NVD6.5
|
| Feb 16, 2025 |
CVE-2025-26767
Qubely: Cross-site scripting
Qubely is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Feb 14, 2025 |
CVE-2024-9601
Qubely – Advanced Gutenberg Blocks: Cross-site scripting
Qubely – Advanced Gutenberg Blocks is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jan 16, 2024 |
CVE-2023-0376
Qubely: Cross-site scripting
Qubely is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Aug 07, 2023 |
CVE-2021-24916
Qubely: A security weakness
Qubely is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Jan 24, 2022 |
CVE-2021-25013
Qubely: Cross-site request forgery
Qubely is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.5
NVD6.5
|