← WordPress Vulnerabilities
WordPress security by component

Qubely

Qubely is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: qubely

CVE-2026-65531: Qubely: A security weakness

Qubely is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.8.14.

PublishedJul 23, 2026
Known safe version> 1.8.14
Safe version
Jul 23, 2026 CVE-2026-65531
Qubely: A security weakness
Qubely is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.8.14.
> 1.8.14
CVE4.8
NVDPending
Apr 08, 2026 CVE-2026-39638
Qubely: Cross-site scripting
Qubely is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.8.14.
> 1.8.14
CVE5.9
NVDPending
Sep 22, 2025 CVE-2025-58663
Qubely: A security weakness
Qubely is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Sep 22, 2025 CVE-2025-58249
Qubely: A security weakness
Qubely is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Mar 11, 2025 CVE-2024-13228
Qubely – Advanced Gutenberg Blocks: Sensitive information exposure
Qubely – Advanced Gutenberg Blocks is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVD6.5
Feb 16, 2025 CVE-2025-26767
Qubely: Cross-site scripting
Qubely is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Feb 14, 2025 CVE-2024-9601
Qubely – Advanced Gutenberg Blocks: Cross-site scripting
Qubely – Advanced Gutenberg Blocks is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jan 16, 2024 CVE-2023-0376
Qubely: Cross-site scripting
Qubely is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Aug 07, 2023 CVE-2021-24916
Qubely: A security weakness
Qubely is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Jan 24, 2022 CVE-2021-25013
Qubely: Cross-site request forgery
Qubely is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD6.5