Description
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
Published: 2026-07-23
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated Broken Access Control flaw exists in the WordPress Qubely plugin for versions 1.8.14 and earlier. The weakness, classified as CWE-862, allows an attacker to access administrative capabilities of the plugin without possessing a valid user account or required permissions. The vulnerable code can expose endpoints that should be protected, potentially enabling illicit configuration changes or data exposure, depending on the implementation of the administrative interfaces.

Affected Systems

WordPress sites running the Qubely plugin from Themeum, with version numbers 1.8.14 or lower, are vulnerable. The plugin is a third‑party WordPress extension; no other plugins or core WordPress components are listed as affected.

Risk and Exploitability

The CVSS score of 4.8 indicates a medium severity overall. The EPSS score of less than 1% suggests the probability of exploitation is low at present, and the vulnerability is not catalogued in CISA's KEV list. Because the flaw is unauthenticated, an attacker can target the affected endpoints over HTTP or HTTPS from any location, without needing prior access or credentials. The simplicity of the required input makes the attack vector remote and low‑effort, though the opportunistic nature of the vulnerability keeps its exploitation likelihood modest.

Generated by OpenCVE AI on August 3, 2026 at 21:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Qubely plugin to the latest version available from Themeum that is newer than 1.8.14.
  • If upgrading is not immediately possible, uninstall or deactivate the Qubely plugin to eliminate the exposed administrative paths.
  • Configure WordPress or the web server to restrict access to any remaining Qubely‑related URLs to administrator users only, for example by using role‑based permissions or access control rules.

Generated by OpenCVE AI on August 3, 2026 at 21:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Themeum
Themeum qubely
Wordpress
Wordpress wordpress
Vendors & Products Themeum
Themeum qubely
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
Title WordPress Qubely plugin <= 1.8.14 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Themeum Qubely
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T15:12:18.787Z

Reserved: 2026-07-22T08:54:08.235Z

Link: CVE-2026-65531

cve-icon Vulnrichment

Updated: 2026-07-23T15:11:56.893Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:46.017

Modified: 2026-07-23T16:17:52.380

Link: CVE-2026-65531

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:00:04Z

Weaknesses