Executive brief
Qubely is a popular WordPress plugin used for building custom page layouts and blocks. A security vulnerability in versions up to 1.8.14 allows an attacker with high-level permissions to inject malicious scripts into the website. If a site visitor or administrator views the affected page, these scripts could be used to redirect users to malicious sites, steal session information, or deface the website.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Themeum Qubely plugin for WordPress (versions <= 1.8.14) due to improper neutralization of input during web page generation. The flaw allows an attacker with high privileges (such as an Author or Editor) to inject malicious HTML or JavaScript payloads into the site's database. These scripts are subsequently executed in the browser of any user who visits the affected page. Exploitation requires the attacker to have network access to the WordPress administrative interface and necessitates some level of user interaction from a victim. As of the advisory date, no official patch has been confirmed.
Affected products
- Themeum Qubely <= 1.8.14
Timeline
- 2026-01-15: other: Vulnerability reported by researcher Jitlada
- 2026-02-14: advisory: Initial advisory published by Patchstack
- 2026-04-08: disclosed: CVE published to NVD