PT-2025-10699 · WordPress · Qubely

Nirmal

+1

·

Published

2025-03-11

·

Updated

2025-05-26

·

CVE-2024-13228

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Qubely – Advanced Gutenberg Blocks plugin for WordPress versions up to and including 1.8.13
Description The issue allows authenticated attackers with Contributor-level access or higher to extract sensitive data from private, pending, scheduled, password-protected, draft, and trashed posts through the qubely get content function. This enables the exposure of confidential information.
Recommendations For Qubely – Advanced Gutenberg Blocks plugin for WordPress versions up to and including 1.8.13, update to a version higher than 1.8.13 to resolve the issue. As a temporary workaround, consider restricting access to the qubely get content function to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-13228

Affected Products

Qubely