Access violation vulnerability in Qubely 1.8.6

The Qubely plugin for WordPress has a security issue in versions up to 1.8.5. This means that someone who is not authorized to do so could use the plugin to send emails with whatever content they choose to whatever email address they choose. This is caused by the Qubely plugin not properly checking to make sure that a contact form block is present and not checking the email fields when using the qubely_send_form_data() function via an AJAX action.

Detected in:

Qubely – Advanced Gutenberg Blocks fixed vulnerable versions: >= * <= 0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.