CVE-2025-4315: CubeWP – All-in-One Dynamic Content Framework <= 1.1.23 - Authenticated (Subscriber+) Privilege Escalation
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is due to the plugin allowing a user to update arbitrary user meta through the updateusermeta() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4315?
CVE-2025-4315 is rated as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-4315?
To mitigate CVE-2025-4315, users should upgrade to a version of the CubeWP All-in-One Dynamic Content Framework plugin newer than 1.1.23.
What systems are affected by CVE-2025-4315?
CVE-2025-4315 affects all versions of the CubeWP All-in-One Dynamic Content Framework plugin for WordPress up to and including 1.1.23.
What kind of vulnerability is CVE-2025-4315?
CVE-2025-4315 is identified as a privilege escalation vulnerability allowing unauthorized user meta updates.
Who is responsible for addressing CVE-2025-4315?
The maintainers of the CubeWP All-in-One Dynamic Content Framework plugin are responsible for addressing CVE-2025-4315 through security updates.