Vulnerability Description
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is due to the plugin allowing a user to update arbitrary user meta through the update_user_meta() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cubewp | Cubewp | < 1.1.24 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/cubewp-framework/tags/1.1.23/cube/claProduct
- https://plugins.trac.wordpress.org/changeset/3306925/cubewp-framework#file2Patch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/430b7e72-72b8-4cf8-99fThird Party Advisory
FAQ
What is CVE-2025-4315?
CVE-2025-4315 is a vulnerability with a CVSS score of 8.8 (HIGH). The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is due to the plugin allowing a user to ...
How severe is CVE-2025-4315?
CVE-2025-4315 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-4315?
Check the references section above for vendor advisories and patch information. Affected products include: Cubewp Cubewp.