Description
The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cubewp_shortcode_taxonomy shortcode in all versions up to, and including, 1.1.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-01-17
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting for Contributor+ users
Action: Immediate Patch
AI Analysis

Impact

The CubeWP Framework is vulnerable to a stored cross‑site scripting flaw that arises when the cubewp_shortcode_taxonomy shortcode is used with malicious attribute values. The weakness stems from insufficient input sanitization and output escaping, allowing an attacker who can add or edit a shortcode to insert arbitrary JavaScript that will run in the browsers of any user who views the affected page. This type of injection can be used to deface a site, steal credentials, session cookies, or perform other malicious actions within the victim’s browser context. The flaw does not grant the attacker direct control of the underlying server or filesystem, but it does allow a contributor‑level attacker to compromise the confidentiality and integrity of page content and potentially impact other users who interact with the compromised page.

Affected Systems

CubeWP Framework, all releases up to and including 1.1.26 are affected. Users running any of these versions are at risk if they can insert or edit the cubewp_shortcode_taxonomy shortcode.

Risk and Exploitability

This vulnerability scores 6.4 on the CVSS scale, indicating a moderate risk level. The EPSS score is below 1%, suggesting that exploitation is currently unlikely, and the flaw is not listed in the CISA KEV catalog. Exploitation requires authenticated access with contributor or higher privileges, and the attacker must be able to place the malicious shortcode in a page that is subsequently viewed by other users. Because the vulnerability is client‑side, it mainly affects user sessions and content integrity rather than system compromise.

Generated by OpenCVE AI on April 20, 2026 at 21:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CubeWP Framework to version 1.1.27 or later; the update removes the stored XSS flaw (CWE‑79) by properly sanitizing shortcode attributes.
  • If an update is not immediately possible, temporarily disable the cubewp_shortcode_taxonomy shortcode or delete all instances of it to eliminate the vulnerable input vector that can lead to XSS (CWE‑79).
  • Adjust role capabilities so that contributor‑level users cannot insert or edit the cubewp_shortcode_taxonomy shortcode, thus limiting exposure to XSS (CWE‑79).

Generated by OpenCVE AI on April 20, 2026 at 21:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Cubewp
Cubewp cubewp
Wordpress
Wordpress wordpress
Vendors & Products Cubewp
Cubewp cubewp
Wordpress
Wordpress wordpress

Sat, 17 Jan 2026 08:30:00 +0000

Type Values Removed Values Added
Description The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cubewp_shortcode_taxonomy shortcode in all versions up to, and including, 1.1.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title CubeWP <= 1.1.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via cubewp_shortcode_taxonomy Shortcode
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Cubewp Cubewp
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:32:03.733Z

Reserved: 2025-08-05T20:04:22.582Z

Link: CVE-2025-8615

cve-icon Vulnrichment

Updated: 2026-01-20T19:18:35.948Z

cve-icon NVD

Status : Deferred

Published: 2026-01-17T09:15:51.850

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-8615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T21:15:20Z

Weaknesses