CubeWP All-in-One Dynamic Content Framework
cpe:2.3:a:cubewp:cubewp:*:*:*:*:wordpress:*:*
- <= 1.1.23
A privilege escalation vulnerability exists in the CubeWP – All-in-One Dynamic Content Framework plugin for WordPress, affecting all versions through 1.1.23. The vulnerability arises because the plugin allows users to update arbitrary user meta using the update_user_meta() function. This capability enables authenticated attackers with Subscriber-level access or higher to elevate their privileges to that of an administrator.
Exploitation of this vulnerability allows authenticated users with Subscriber-level access to gain administrative privileges.
Users can update to version 1.1.24 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.