Executive brief
Qubely is a popular Gutenberg block toolkit and page builder plugin for WordPress websites. A security flaw in versions 1.8.14 and earlier allows unauthenticated users to bypass access controls, potentially allowing them to perform actions or access data they should not be authorized to reach. While the impact is considered moderate, it could allow unauthorized changes to site content or settings.
Technical details
A broken access control vulnerability exists in the Themeum Qubely plugin for WordPress (versions <= 1.8.14) due to missing authorization checks (CWE-862). The flaw allows an unauthenticated remote attacker to execute functions or actions that should be restricted to higher-privileged users. The attack vector is network-based and requires no user interaction, though the CVSS assessment indicates high attack complexity. As of the advisory date, no official patch has been confirmed, and users are advised to monitor for updates from the developer.
Affected products
- Themeum Qubely <= 1.8.14
Timeline
- 2026-06-12: other: Vulnerability reported by researcher
- 2026-07-23: disclosed: Vulnerability published by Patchstack and NVD