Information Exposure Vulnerability in CubeWP Dynamic Content Framework for WordPress
CVE-2025-6461
4.3MEDIUM
What is CVE-2025-6461?
The CubeWP β All-in-One Dynamic Content Framework plugin for WordPress contains a vulnerability that allows unauthenticated attackers to access sensitive data. This issue arises from inadequate control over the posts displayed via the search feature, located in class-cubewp-search-ajax-hooks.php. Attackers can exploit this flaw to extract information from password-protected, private, or draft posts, posing a significant risk to user privacy and data integrity.
Affected Version(s)
CubeWP Framework 0 <= 1.1.27