Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a through <= 1.8.12.
Published: 2025-02-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation allows an attacker to store malicious JavaScript code in data fields managed by the Qubely plugin. When other visitors view pages that retrieve and render this stored content, the script executes in their browsers, potentially allowing the attacker to deface the page or exfiltrate data. Based on the description, it is inferred that the stored payload will run with the privileges of the user viewing the affected content.

Affected Systems

WordPress sites that have installed Themeum Qubely version 1.8.12 or earlier are affected. Any site using the plugin within this version range stores user data that may carry unsanitized payloads, creating a risk for all visitors who view the compromised content.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5, indicating moderate severity. Its EPSS score is less than 1 %, suggesting a low likelihood of current exploitation. The flaw is not listed in the CISA KEV catalog. The attack vector is likely a web‑application based stored XSS where an attacker injects malicious code into a Qubely data field that is later rendered for other users.

Generated by OpenCVE AI on May 2, 2026 at 09:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Qubely plugin to a version newer than 1.8.12 if a fix has been released.
  • If an upgrade is not immediately possible, disable or uninstall the Qubely plugin to eliminate the vulnerable functionality from the site.
  • Deploy a Web Application Firewall rule or a content‑security‑policy that detects or evicts script payloads in stored content to mitigate the impact while remediation is pending.

Generated by OpenCVE AI on May 2, 2026 at 09:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4240 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely – Advanced Gutenberg Blocks allows Stored XSS. This issue affects Qubely – Advanced Gutenberg Blocks: from n/a through 1.8.12.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely – Advanced Gutenberg Blocks allows Stored XSS. This issue affects Qubely – Advanced Gutenberg Blocks: from n/a through 1.8.12. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a through <= 1.8.12.
Title WordPress Qubely – Advanced Gutenberg Blocks plugin <= 1.8.12 - Cross Site Scripting (XSS) vulnerability WordPress Qubely plugin <= 1.8.12 - Cross Site Scripting (XSS) vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00024}

epss

{'score': 0.00026}


Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00054}

epss

{'score': 0.00024}


Fri, 23 May 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Themeum
Themeum qubely
CPEs cpe:2.3:a:themeum:qubely:*:*:*:*:*:wordpress:*:*
Vendors & Products Themeum
Themeum qubely

Tue, 18 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 16 Feb 2025 22:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely – Advanced Gutenberg Blocks allows Stored XSS. This issue affects Qubely – Advanced Gutenberg Blocks: from n/a through 1.8.12.
Title WordPress Qubely – Advanced Gutenberg Blocks plugin <= 1.8.12 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:40.566Z

Reserved: 2025-02-14T06:53:32.111Z

Link: CVE-2025-26767

cve-icon Vulnrichment

Updated: 2025-02-18T17:24:41.564Z

cve-icon NVD

Status : Modified

Published: 2025-02-16T23:15:11.350

Modified: 2026-04-23T15:25:56.697

Link: CVE-2025-26767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:15:26Z

Weaknesses