Impact
An unauthenticated Broken Access Control flaw exists in the WordPress Qubely plugin for versions 1.8.14 and earlier. The weakness, classified as CWE-862, allows an attacker to access administrative capabilities of the plugin without possessing a valid user account or required permissions. The vulnerable code can expose endpoints that should be protected, potentially enabling illicit configuration changes or data exposure, depending on the implementation of the administrative interfaces.
Affected Systems
WordPress sites running the Qubely plugin from Themeum, with version numbers 1.8.14 or lower, are vulnerable. The plugin is a third‑party WordPress extension; no other plugins or core WordPress components are listed as affected.
Risk and Exploitability
The CVSS score of 4.8 indicates a medium severity overall. The EPSS score of less than 1% suggests the probability of exploitation is low at present, and the vulnerability is not catalogued in CISA's KEV list. Because the flaw is unauthenticated, an attacker can target the affected endpoints over HTTP or HTTPS from any location, without needing prior access or credentials. The simplicity of the required input makes the attack vector remote and low‑effort, though the opportunistic nature of the vulnerability keeps its exploitation likelihood modest.
OpenCVE Enrichment