Input validation vulnerability in CubeWP – All-in-One Dynamic Content Framework 1.1.26

The CubeWP plugin for WordPress has a security issue in versions 1.1.26 and below. This is because it does not properly clean up the input and output of web scripts, making it possible for attackers to inject their own scripts into pages. This can be done by someone with contributor-level access or higher, and the injected scripts will run whenever a user visits the affected page.

Detected in:

CubeWP – All-in-One Dynamic Content Framework fixed vulnerable versions: >= * <= 1.1.26

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.