CubeWP All-in-One Dynamic Content Framework Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability exists in the CubeWP – All-in-One Dynamic Content Framework plugin for WordPress, affecting all versions through 1.1.23. The vulnerability arises because the plugin allows users to update arbitrary user meta using the update_user_meta() function. This capability enables authenticated attackers with Subscriber-level access or higher to elevate their privileges to that of an administrator.

Impact

Exploitation of this vulnerability allows authenticated users with Subscriber-level access to gain administrative privileges.

Remediation

Users can update to version 1.1.24 or a newer patched version to address this vulnerability.

Added: Jun 11, 2025, 10:17 AM
Updated: Jun 11, 2025, 10:17 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
5.0
exploitability
6.1
remediation
7.7
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.